General

  • Target

    a2ff9b452041a6ff6097db779da26d70_JaffaCakes118

  • Size

    455KB

  • Sample

    240612-3tlfwawbmc

  • MD5

    a2ff9b452041a6ff6097db779da26d70

  • SHA1

    d9fb90605868c19cdc91c556fb9abfcd09fcdff5

  • SHA256

    c4d9db58c442972cbcb09632bd06b477c6a33f3827a00ac0ec2baeb6a0e6e9cc

  • SHA512

    2c2012fb5821a26d3aa4f5bb645d087978b846ddecd87cc5c4ece039dbac011f44bcf263fbfc383f5546d906391c9c5d5af7e81d7aa92427832de107505c3867

  • SSDEEP

    12288:bRVbfvJSlmOPufGjKH2KcDx/2aTxryFM0v+YXO:bfNonjKH2KcF/RM2

Score
10/10

Malware Config

Targets

    • Target

      a2ff9b452041a6ff6097db779da26d70_JaffaCakes118

    • Size

      455KB

    • MD5

      a2ff9b452041a6ff6097db779da26d70

    • SHA1

      d9fb90605868c19cdc91c556fb9abfcd09fcdff5

    • SHA256

      c4d9db58c442972cbcb09632bd06b477c6a33f3827a00ac0ec2baeb6a0e6e9cc

    • SHA512

      2c2012fb5821a26d3aa4f5bb645d087978b846ddecd87cc5c4ece039dbac011f44bcf263fbfc383f5546d906391c9c5d5af7e81d7aa92427832de107505c3867

    • SSDEEP

      12288:bRVbfvJSlmOPufGjKH2KcDx/2aTxryFM0v+YXO:bfNonjKH2KcF/RM2

    Score
    10/10
    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Scheduled Task/Job

1
T1053

Privilege Escalation

Scheduled Task/Job

1
T1053

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks