Threat Advisory

The Jaca Framework Insights into a Malicious Document Distributing

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A recent discovery by researcher specialists unveiled a malicious file named "Application to Consulate General.doc." This document is identified as distributing the Jaca framework, employing a scheme similar to previous attacks. Notably, the Jaca sample within the file contains a DLL named "NewRegdlTest.dll," with exports including "DllCanUnLoadNow" and "DllUnregisterServer," alongside a mutex labeled "08808." Additionally, a scheduled task titled "pre-staged app cleanup" is set to run from the directory %TEMP%\CommonFiles, utilizing "mscorlib.dll" and "DllCanUnLoadNow." Further investigation revealed that the C2 domain associated with this malicious activity is "trigershop[.]info."[/subscribe_to_unlock_form]

Summary:

A recent discovery by researcher specialists unveiled a malicious file named "Application to Consulate General.doc." This document is identified as distributing the Jaca framework, employing a scheme similar to previous attacks. Notably, the Jaca sample within the file contains a DLL named "NewRegdlTest.dll," with exports including "DllCanUnLoadNow" and "DllUnregisterServer," alongside a mutex labeled "08808." Additionally, a scheduled task titled "pre-staged app cleanup" is set to run from the directory %TEMP%\CommonFiles, utilizing "mscorlib.dll" and "DllCanUnLoadNow." Further investigation revealed that the C2 domain associated with this malicious activity is "trigershop[.]info."[emaillocker id="1283"]

Threat Profile:

 

References:

Eventus Security Threat Research & Development Team

[/emaillocker]
crossmenu