General

  • Target

    a41a425b9aa3dcb50ea244ff90cef59d_JaffaCakes118

  • Size

    331KB

  • Sample

    240613-gq7zta1anl

  • MD5

    a41a425b9aa3dcb50ea244ff90cef59d

  • SHA1

    2d1c8cfba8e5ef11a2a5144346f8102c3c9db805

  • SHA256

    928d06ae692be5a216946aa53308e34b920cdd65eb1eb1f7aad9d4edf779c8b6

  • SHA512

    6b82375eb4645cc8e615c4699fb4eeada8b4a0f50b89bd512810c9c1d643977ae1e5472ee2ea2d8cfb69133381120267db5cd863a10746843bed79e0d5a88334

  • SSDEEP

    6144:R6tnHIghzbAam9iliAotWWfUwwQWzyq2L9OATfzSskQBi:+HrhzW3Jq49zfGQBi

Malware Config

Targets

    • Target

      a41a425b9aa3dcb50ea244ff90cef59d_JaffaCakes118

    • Size

      331KB

    • MD5

      a41a425b9aa3dcb50ea244ff90cef59d

    • SHA1

      2d1c8cfba8e5ef11a2a5144346f8102c3c9db805

    • SHA256

      928d06ae692be5a216946aa53308e34b920cdd65eb1eb1f7aad9d4edf779c8b6

    • SHA512

      6b82375eb4645cc8e615c4699fb4eeada8b4a0f50b89bd512810c9c1d643977ae1e5472ee2ea2d8cfb69133381120267db5cd863a10746843bed79e0d5a88334

    • SSDEEP

      6144:R6tnHIghzbAam9iliAotWWfUwwQWzyq2L9OATfzSskQBi:+HrhzW3Jq49zfGQBi

    • BetaBot

      Beta Bot is a Trojan that infects computers and disables Antivirus.

    • Modifies firewall policy service

    • Sets file execution options in registry

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Adds Run key to start application

    • Checks whether UAC is enabled

    • Suspicious use of NtSetInformationThreadHideFromDebugger

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Defense Evasion

Modify Registry

7
T1112

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Discovery

Query Registry

3
T1012

System Information Discovery

4
T1082

Tasks