General

  • Target

    99daf6981ed0868d09623c8463847c9a_JaffaCakes118

  • Size

    987KB

  • Sample

    240606-dj1qdagc25

  • MD5

    99daf6981ed0868d09623c8463847c9a

  • SHA1

    ad9ce6e2dc54be25d7b23c8902a549a2897e2fef

  • SHA256

    2f60124860d5be9579a4a37ed8e8800197f77dfa7292ea79215897aa1f5aa81a

  • SHA512

    8e3b74ed0189f0528c398de4772e77c7b9019e1ed6a281bbd41663778990eb4a1d6ba0a0006e15a14e52d3a8d237f8c1981a1447a9a267de50aa8f1ffe776965

  • SSDEEP

    24576:CVHchfFcSTdS1ZikTqpaIJvzSqbY/0Z2ZlECMNXkTlzvmJL8:CV8hf6STw1ZlQauvzSq01ICe6zvm

Malware Config

Targets

    • Target

      99daf6981ed0868d09623c8463847c9a_JaffaCakes118

    • Size

      987KB

    • MD5

      99daf6981ed0868d09623c8463847c9a

    • SHA1

      ad9ce6e2dc54be25d7b23c8902a549a2897e2fef

    • SHA256

      2f60124860d5be9579a4a37ed8e8800197f77dfa7292ea79215897aa1f5aa81a

    • SHA512

      8e3b74ed0189f0528c398de4772e77c7b9019e1ed6a281bbd41663778990eb4a1d6ba0a0006e15a14e52d3a8d237f8c1981a1447a9a267de50aa8f1ffe776965

    • SSDEEP

      24576:CVHchfFcSTdS1ZikTqpaIJvzSqbY/0Z2ZlECMNXkTlzvmJL8:CV8hf6STw1ZlQauvzSq01ICe6zvm

    • Dridex

      Dridex(known as Bugat/Cridex) is a form of malware that specializes in stealing bank credentials.

    • Dridex Shellcode

      Detects Dridex Payload shellcode injected in Explorer process.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

System Information Discovery

1
T1082

Query Registry

1
T1012

Tasks