General

  • Target

    9b3250409072ce5b4e4bc467f29102d2_JaffaCakes118

  • Size

    612KB

  • Sample

    240610-s57s5s1hra

  • MD5

    9b3250409072ce5b4e4bc467f29102d2

  • SHA1

    86a2fad69241a68a129c25531d5aea8ba2304bc3

  • SHA256

    24f089cd7b8348eea7f18b3d69fe7bd4d000f1a4c2ba7889a5e133e9862cc1e2

  • SHA512

    e7101b2f5d63410920d3b58e2c12ca00edba1351aa7d31cfa139af49f21f25fe328c0e446ee2885b046ca52083dfb012a6ea7555d86c098287dc1ff91d89b31f

  • SSDEEP

    12288:RfEKhhYNpXXreuGFzpY2zkF9a37WSTUE8vcbI91BntKpzRrYBMKj:RcKMNpHqDJhLu35DzKJd

Malware Config

Targets

    • Target

      9b3250409072ce5b4e4bc467f29102d2_JaffaCakes118

    • Size

      612KB

    • MD5

      9b3250409072ce5b4e4bc467f29102d2

    • SHA1

      86a2fad69241a68a129c25531d5aea8ba2304bc3

    • SHA256

      24f089cd7b8348eea7f18b3d69fe7bd4d000f1a4c2ba7889a5e133e9862cc1e2

    • SHA512

      e7101b2f5d63410920d3b58e2c12ca00edba1351aa7d31cfa139af49f21f25fe328c0e446ee2885b046ca52083dfb012a6ea7555d86c098287dc1ff91d89b31f

    • SSDEEP

      12288:RfEKhhYNpXXreuGFzpY2zkF9a37WSTUE8vcbI91BntKpzRrYBMKj:RcKMNpHqDJhLu35DzKJd

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks