General

  • Target

    af2925f1ce5641759933ff4585ed75d0_JaffaCakes118

  • Size

    69KB

  • Sample

    240615-s7s3rswcle

  • MD5

    af2925f1ce5641759933ff4585ed75d0

  • SHA1

    cb8c025341929f65e16973fccf56715bdf6ae23b

  • SHA256

    f5d3b645c30b9783808d55dee96a790683723e82885070cb1fbbe7c50753e5fa

  • SHA512

    3f21b2ec623f8a1f288b08fcc33aaddd37356010f9ab8d3cac529bcf960584f53e7bbe6009bfa0d24327853a659e23d8984d605565a95b0f485bb183db02bd19

  • SSDEEP

    1536:5zzzzzzzzV9rXounV98hbHnAXMqqUM2Lkvd6:/BounVyFHCMqqMLkvd

Score
10/10

Malware Config

Targets

    • Target

      af2925f1ce5641759933ff4585ed75d0_JaffaCakes118

    • Size

      69KB

    • MD5

      af2925f1ce5641759933ff4585ed75d0

    • SHA1

      cb8c025341929f65e16973fccf56715bdf6ae23b

    • SHA256

      f5d3b645c30b9783808d55dee96a790683723e82885070cb1fbbe7c50753e5fa

    • SHA512

      3f21b2ec623f8a1f288b08fcc33aaddd37356010f9ab8d3cac529bcf960584f53e7bbe6009bfa0d24327853a659e23d8984d605565a95b0f485bb183db02bd19

    • SSDEEP

      1536:5zzzzzzzzV9rXounV98hbHnAXMqqUM2Lkvd6:/BounVyFHCMqqMLkvd

    Score
    6/10
    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks