General

  • Target

    a0a31dd15e1039fc801a7fdb480ef91a_JaffaCakes118

  • Size

    757KB

  • Sample

    240612-pfgc4svapd

  • MD5

    a0a31dd15e1039fc801a7fdb480ef91a

  • SHA1

    426062eb6e6bca63258d3dbce674a5547ee1d507

  • SHA256

    8f6b47ef4407cf14719e43ff46ff4a090269a7570509852a2366ed756f3b0aaf

  • SHA512

    006d53ea10c55b846f7dd8d5f470c0e1bd3c7d991fe7588dc4939aeb5bea663209cb1e879ede6804017f80327edca3792c4a72d46e94f4a662c2d8cb8d4554d6

  • SSDEEP

    12288:+BZl1vvNQSnTlBZl1vvNQSnTKvIT7XPa5xLaggSH1Lx0tMcqgcwwwlasqJX:W1vvNQQTz1vvNQQTKvea5xLagVH1LCqb

Malware Config

Targets

    • Target

      a0a31dd15e1039fc801a7fdb480ef91a_JaffaCakes118

    • Size

      757KB

    • MD5

      a0a31dd15e1039fc801a7fdb480ef91a

    • SHA1

      426062eb6e6bca63258d3dbce674a5547ee1d507

    • SHA256

      8f6b47ef4407cf14719e43ff46ff4a090269a7570509852a2366ed756f3b0aaf

    • SHA512

      006d53ea10c55b846f7dd8d5f470c0e1bd3c7d991fe7588dc4939aeb5bea663209cb1e879ede6804017f80327edca3792c4a72d46e94f4a662c2d8cb8d4554d6

    • SSDEEP

      12288:+BZl1vvNQSnTlBZl1vvNQSnTKvIT7XPa5xLaggSH1Lx0tMcqgcwwwlasqJX:W1vvNQQTz1vvNQQTKvea5xLagVH1LCqb

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks