General

  • Target

    7ae1900d594e89f2930a2237f24941a6_JaffaCakes118

  • Size

    321KB

  • Sample

    240527-27ed2sef95

  • MD5

    7ae1900d594e89f2930a2237f24941a6

  • SHA1

    bd83fbb6b224640193bb7dcb66db2a586727e771

  • SHA256

    66403c815d78c45f3e4306233821231ec99538f12982ec7d959c9708401432d3

  • SHA512

    fe6302a497ed581c17327a02d12081a4064b2cc4e1254ff74b7f595a634a5b3ad0b68626d22a219a32d5aa372b22c40284c6101c070a2ee3c57b90f7b39dd311

  • SSDEEP

    6144:6p5GHKqSccAXTIzUzWvxv7vV+G7zPoAz0Q54HeyJAud+V3Oj:6LGHKDccAX0AWvxzvV+zAz03HFB

Score
10/10

Malware Config

Targets

    • Target

      7ae1900d594e89f2930a2237f24941a6_JaffaCakes118

    • Size

      321KB

    • MD5

      7ae1900d594e89f2930a2237f24941a6

    • SHA1

      bd83fbb6b224640193bb7dcb66db2a586727e771

    • SHA256

      66403c815d78c45f3e4306233821231ec99538f12982ec7d959c9708401432d3

    • SHA512

      fe6302a497ed581c17327a02d12081a4064b2cc4e1254ff74b7f595a634a5b3ad0b68626d22a219a32d5aa372b22c40284c6101c070a2ee3c57b90f7b39dd311

    • SSDEEP

      6144:6p5GHKqSccAXTIzUzWvxv7vV+G7zPoAz0Q54HeyJAud+V3Oj:6LGHKDccAX0AWvxzvV+zAz03HFB

    Score
    10/10
    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops desktop.ini file(s)

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks