General

  • Target

    aee5704ab8e1ef4484caef048a2e286f_JaffaCakes118

  • Size

    652KB

  • Sample

    240615-rzpjyaxgrr

  • MD5

    aee5704ab8e1ef4484caef048a2e286f

  • SHA1

    e023f6678b315e5b48beeaa0f3239adc15aaf59f

  • SHA256

    d07f8aa03c96baaacb17564a7bd9d8be6b7effb347a1a98e1ea201a528e4ff8f

  • SHA512

    184645be06e5945d09c1c0bb0756e4943757d44db203928e025c6f5147c516123d9fc2221f1cd53e684edf170a39f7c3bfc58ba20a7824a21a77d21d03be36ef

  • SSDEEP

    12288:2lAb5lthGT76dsIqVpYO+NyEcQQ+9OoZyXTGMFTBJPfiIR:2azrGT7muSiEc+9OoGG4pqI

Malware Config

Targets

    • Target

      aee5704ab8e1ef4484caef048a2e286f_JaffaCakes118

    • Size

      652KB

    • MD5

      aee5704ab8e1ef4484caef048a2e286f

    • SHA1

      e023f6678b315e5b48beeaa0f3239adc15aaf59f

    • SHA256

      d07f8aa03c96baaacb17564a7bd9d8be6b7effb347a1a98e1ea201a528e4ff8f

    • SHA512

      184645be06e5945d09c1c0bb0756e4943757d44db203928e025c6f5147c516123d9fc2221f1cd53e684edf170a39f7c3bfc58ba20a7824a21a77d21d03be36ef

    • SSDEEP

      12288:2lAb5lthGT76dsIqVpYO+NyEcQQ+9OoZyXTGMFTBJPfiIR:2azrGT7muSiEc+9OoGG4pqI

    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks