General

  • Target

    a0e983ac9bc736fc036deb22f66fac7b_JaffaCakes118

  • Size

    839KB

  • Sample

    240612-q9vy2a1dpl

  • MD5

    a0e983ac9bc736fc036deb22f66fac7b

  • SHA1

    263992909fcfbbb3f4bebbd72de6076e7bbbc35e

  • SHA256

    d02ac25c541c1db2c472c3911c85102d1696ea91e7c7f91d5223f05c9578a4d6

  • SHA512

    7c7f11eb5d55291f4a3cd21cd486b7338c5eb2cfe8f94217c0cd6d75919994b6b36ddb7c829d9c596df9f227dcdc8d3a1ff7be42c35b9dc3f525fba4ff60edb2

  • SSDEEP

    12288:+bOrWJ/dY02/a7yOWzNc4GG1bGd6H5FX+K3gszVXVxzIcz5muGpia2QUVH:HyV9sa77m5b1bGqdVFxzb5mlA

Malware Config

Targets

    • Target

      a0e983ac9bc736fc036deb22f66fac7b_JaffaCakes118

    • Size

      839KB

    • MD5

      a0e983ac9bc736fc036deb22f66fac7b

    • SHA1

      263992909fcfbbb3f4bebbd72de6076e7bbbc35e

    • SHA256

      d02ac25c541c1db2c472c3911c85102d1696ea91e7c7f91d5223f05c9578a4d6

    • SHA512

      7c7f11eb5d55291f4a3cd21cd486b7338c5eb2cfe8f94217c0cd6d75919994b6b36ddb7c829d9c596df9f227dcdc8d3a1ff7be42c35b9dc3f525fba4ff60edb2

    • SSDEEP

      12288:+bOrWJ/dY02/a7yOWzNc4GG1bGd6H5FX+K3gszVXVxzIcz5muGpia2QUVH:HyV9sa77m5b1bGqdVFxzb5mlA

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Adds Run key to start application

    • Drops desktop.ini file(s)

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks