General

  • Target

    b4835aa34d4d7cffa8ad9a21fcdbdd78_JaffaCakes118

  • Size

    684KB

  • Sample

    240616-wvwjxavglq

  • MD5

    b4835aa34d4d7cffa8ad9a21fcdbdd78

  • SHA1

    1eb444f23d1a3661f9d6a68c4bf56abc99288776

  • SHA256

    750148d79d393e656f34388d16b2f5494147fa49eb7258964e1a10dd87331147

  • SHA512

    7b3fc1786964c1fbca538103e945c9db5cb5131586f24c60c2125ebc4bea5ada581508cb06157d6561ed79dba173a74bdc0fd455db65982e87635542e16f9f16

  • SSDEEP

    12288:BzEYe5sWd9m2KHSCdZF1MmY9zPmAlVf3/Eoj3nh/wSvBle6bRy8RWY7lwukUFDuH:NeKacZF1MzPftsBSX9lyKWYlDu33

Malware Config

Targets

    • Target

      b4835aa34d4d7cffa8ad9a21fcdbdd78_JaffaCakes118

    • Size

      684KB

    • MD5

      b4835aa34d4d7cffa8ad9a21fcdbdd78

    • SHA1

      1eb444f23d1a3661f9d6a68c4bf56abc99288776

    • SHA256

      750148d79d393e656f34388d16b2f5494147fa49eb7258964e1a10dd87331147

    • SHA512

      7b3fc1786964c1fbca538103e945c9db5cb5131586f24c60c2125ebc4bea5ada581508cb06157d6561ed79dba173a74bdc0fd455db65982e87635542e16f9f16

    • SSDEEP

      12288:BzEYe5sWd9m2KHSCdZF1MmY9zPmAlVf3/Eoj3nh/wSvBle6bRy8RWY7lwukUFDuH:NeKacZF1MzPftsBSX9lyKWYlDu33

    • AdWind

      A Java-based RAT family operated as malware-as-a-service.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

2
T1112

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Tasks