General

  • Target

    a433e7322813adce718a67829a6ccfb8_JaffaCakes118

  • Size

    531KB

  • Sample

    240613-g8qs9axdnb

  • MD5

    a433e7322813adce718a67829a6ccfb8

  • SHA1

    0ca10ca7af1780983cc7146008093e5e0fb7f74e

  • SHA256

    44210da3f454a4a2e11d6e384aa0d7588288d05f2ddbfe1bce4861a2ecffdc4d

  • SHA512

    4f48458c1ed5483c628b471d7c6e81b0cf738660543e09589f3e1f35bb1b8d8a51c36610a2ce86da92cdf7acd8efbedd388f3d7598568240e88d512d54e3e7e7

  • SSDEEP

    12288:aNXU42a5EIoiY8AuqdOeASJdxuz/w2tJeZw6q7+6a6:QTYuk0SJdew2Xcwgs

Malware Config

Targets

    • Target

      a433e7322813adce718a67829a6ccfb8_JaffaCakes118

    • Size

      531KB

    • MD5

      a433e7322813adce718a67829a6ccfb8

    • SHA1

      0ca10ca7af1780983cc7146008093e5e0fb7f74e

    • SHA256

      44210da3f454a4a2e11d6e384aa0d7588288d05f2ddbfe1bce4861a2ecffdc4d

    • SHA512

      4f48458c1ed5483c628b471d7c6e81b0cf738660543e09589f3e1f35bb1b8d8a51c36610a2ce86da92cdf7acd8efbedd388f3d7598568240e88d512d54e3e7e7

    • SSDEEP

      12288:aNXU42a5EIoiY8AuqdOeASJdxuz/w2tJeZw6q7+6a6:QTYuk0SJdew2Xcwgs

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks