General

  • Target

    9327d8a117e01b69e61a7690fed88818_JaffaCakes118

  • Size

    6.9MB

  • Sample

    240604-ay6cmafa4t

  • MD5

    9327d8a117e01b69e61a7690fed88818

  • SHA1

    394ab8c6728e2ffa1381e6afe3e52d15d44c6965

  • SHA256

    b7691c583984fe210bbc5ce7291dd2a80dd969d7b33e25863c99311303febbc3

  • SHA512

    b58962e98750064aa16e738b81ac76c39206ae6bb65c9ddf01a6cdd5bd2d979522bbb7a61544efe87ec0d6475965206d57459961214848d020acab25f113c47d

  • SSDEEP

    98304:aQ8/Py9frbxvXKKkGxTVhG2+9Mpq6vQt/Ibt1YcyDgs:L8nylrZtjG9MpqINns

Malware Config

Targets

    • Target

      9327d8a117e01b69e61a7690fed88818_JaffaCakes118

    • Size

      6.9MB

    • MD5

      9327d8a117e01b69e61a7690fed88818

    • SHA1

      394ab8c6728e2ffa1381e6afe3e52d15d44c6965

    • SHA256

      b7691c583984fe210bbc5ce7291dd2a80dd969d7b33e25863c99311303febbc3

    • SHA512

      b58962e98750064aa16e738b81ac76c39206ae6bb65c9ddf01a6cdd5bd2d979522bbb7a61544efe87ec0d6475965206d57459961214848d020acab25f113c47d

    • SSDEEP

      98304:aQ8/Py9frbxvXKKkGxTVhG2+9Mpq6vQt/Ibt1YcyDgs:L8nylrZtjG9MpqINns

    • Glupteba

      Glupteba is a modular loader written in Golang with various components.

    • Glupteba payload

    • Windows security bypass

    • Modifies Windows Firewall

    • Executes dropped EXE

    • Loads dropped DLL

    • Windows security modification

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Impair Defenses

3
T1562

Disable or Modify Tools

2
T1562.001

Disable or Modify System Firewall

1
T1562.004

Modify Registry

3
T1112

Discovery

System Information Discovery

1
T1082

Tasks