General

  • Target

    142e3778739a869cf9e791442b7bf675_JaffaCakes118

  • Size

    16KB

  • Sample

    240504-yaglcsbf75

  • MD5

    142e3778739a869cf9e791442b7bf675

  • SHA1

    c0a97a2b84ebb8b7034e776102e078f118aec4ed

  • SHA256

    e6454ecc1ee77ea4310736c6f2ec5eb169b94c039a90f2bc24231b8a7b2b5357

  • SHA512

    f503da8168e802c7495c8a2e6c4c9085b68dd92176dd977babeff5c51ea1d26846f910a04c425c851fc248c34894a504e5872bc48b5513af1bf69ef4328004ca

  • SSDEEP

    384:FKxvDuPNItH19GTXjdhRLuujYcV6AUwJFZb:F44atV9AhlfYcV6Dw9b

Malware Config

Targets

    • Target

      142e3778739a869cf9e791442b7bf675_JaffaCakes118

    • Size

      16KB

    • MD5

      142e3778739a869cf9e791442b7bf675

    • SHA1

      c0a97a2b84ebb8b7034e776102e078f118aec4ed

    • SHA256

      e6454ecc1ee77ea4310736c6f2ec5eb169b94c039a90f2bc24231b8a7b2b5357

    • SHA512

      f503da8168e802c7495c8a2e6c4c9085b68dd92176dd977babeff5c51ea1d26846f910a04c425c851fc248c34894a504e5872bc48b5513af1bf69ef4328004ca

    • SSDEEP

      384:FKxvDuPNItH19GTXjdhRLuujYcV6AUwJFZb:F44atV9AhlfYcV6Dw9b

    • LoaderBot

      LoaderBot is a loader written in .NET downloading and executing miners.

    • LoaderBot executable

    • Drops startup file

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

Modify Registry

1
T1112

Tasks