General

  • Target

    9976f599e88407d195ffc0ecce4ed38f_JaffaCakes118

  • Size

    497KB

  • Sample

    240605-2xlelsbc4t

  • MD5

    9976f599e88407d195ffc0ecce4ed38f

  • SHA1

    4a6f3eb8a1908caeef37628116c4c9caebf885b6

  • SHA256

    ea7b64e60ffd4537f9978a3df9430e3eb3f5395ef632f16fd17f5945b829484b

  • SHA512

    52cf9ed994659bf3079de762cdd27de83a79bd2a1b01334c80353777719988db538f850089eb24a9f72b2b2a2b9e050f776ef80154220d5679b99895493ec27d

  • SSDEEP

    12288:/uCTD7DIh2R8cud2g4GGbIheZHT/SyMPLA8oMXC4NL:zfIh2gANGGb8IM0hMXb

Malware Config

Targets

    • Target

      9976f599e88407d195ffc0ecce4ed38f_JaffaCakes118

    • Size

      497KB

    • MD5

      9976f599e88407d195ffc0ecce4ed38f

    • SHA1

      4a6f3eb8a1908caeef37628116c4c9caebf885b6

    • SHA256

      ea7b64e60ffd4537f9978a3df9430e3eb3f5395ef632f16fd17f5945b829484b

    • SHA512

      52cf9ed994659bf3079de762cdd27de83a79bd2a1b01334c80353777719988db538f850089eb24a9f72b2b2a2b9e050f776ef80154220d5679b99895493ec27d

    • SSDEEP

      12288:/uCTD7DIh2R8cud2g4GGbIheZHT/SyMPLA8oMXC4NL:zfIh2gANGGb8IM0hMXb

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Obfuscated with Agile.Net obfuscator

      Detects use of the Agile.Net commercial obfuscator, which is capable of entity renaming and control flow obfuscation.

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks