General

  • Target

    b13278b22966a77e73ba4e2d7b21c663_JaffaCakes118

  • Size

    320KB

  • Sample

    240616-cazahsycpq

  • MD5

    b13278b22966a77e73ba4e2d7b21c663

  • SHA1

    a698b00e96fc5695f30ce86f2cffafdc801627b0

  • SHA256

    95dd9969858c4190c605a39044ab1f42d42266dbf8881ee6ef5ef9ab072efc86

  • SHA512

    9e2420d8f0271a5f6adc02942d0160f10edcfe84080b4c482ea87f21086fbd828b2dfa24f100ab517750b487830968931dd023490566eb5f4148696efc0a7be2

  • SSDEEP

    6144:OZ5GHKqSccAXTIzUzWvxv7vV+G7zPoAz0Q54HeyJAud+V3Oj:ObGHKDccAX0AWvxzvV+zAz03HFB

Score
10/10

Malware Config

Targets

    • Target

      b13278b22966a77e73ba4e2d7b21c663_JaffaCakes118

    • Size

      320KB

    • MD5

      b13278b22966a77e73ba4e2d7b21c663

    • SHA1

      a698b00e96fc5695f30ce86f2cffafdc801627b0

    • SHA256

      95dd9969858c4190c605a39044ab1f42d42266dbf8881ee6ef5ef9ab072efc86

    • SHA512

      9e2420d8f0271a5f6adc02942d0160f10edcfe84080b4c482ea87f21086fbd828b2dfa24f100ab517750b487830968931dd023490566eb5f4148696efc0a7be2

    • SSDEEP

      6144:OZ5GHKqSccAXTIzUzWvxv7vV+G7zPoAz0Q54HeyJAud+V3Oj:ObGHKDccAX0AWvxzvV+zAz03HFB

    Score
    10/10
    • Imminent RAT

      Remote-access trojan based on Imminent Monitor remote admin software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops desktop.ini file(s)

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Tasks