General

  • Target

    ba78189a1e1389cdcf5478ec3ec0f8c2_JaffaCakes118

  • Size

    1.2MB

  • Sample

    240618-jc3t2stbke

  • MD5

    ba78189a1e1389cdcf5478ec3ec0f8c2

  • SHA1

    0b5278a45fb91bddbc33841fcdd4074bda3377f2

  • SHA256

    6e595a15eb50e2fc6c4d76554b992ab4a81be446c4b8b450e84ed308f7dcf341

  • SHA512

    f59f0409426fad48a60cfed2cdd33d523699f7c23fb4dfb1dccc5525a7c5be2dacb5c612debb73a2d0af69748fe78f2276c5653feb7b655e794205af11ec692d

  • SSDEEP

    24576:5VHchfFcSTdS1ZikTqpaIJvzSqbY/0Z2ZlECMNXkTlzvmJL8:5V8hf6STw1ZlQauvzSq01ICe6zvm

Malware Config

Targets

    • Target

      ba78189a1e1389cdcf5478ec3ec0f8c2_JaffaCakes118

    • Size

      1.2MB

    • MD5

      ba78189a1e1389cdcf5478ec3ec0f8c2

    • SHA1

      0b5278a45fb91bddbc33841fcdd4074bda3377f2

    • SHA256

      6e595a15eb50e2fc6c4d76554b992ab4a81be446c4b8b450e84ed308f7dcf341

    • SHA512

      f59f0409426fad48a60cfed2cdd33d523699f7c23fb4dfb1dccc5525a7c5be2dacb5c612debb73a2d0af69748fe78f2276c5653feb7b655e794205af11ec692d

    • SSDEEP

      24576:5VHchfFcSTdS1ZikTqpaIJvzSqbY/0Z2ZlECMNXkTlzvmJL8:5V8hf6STw1ZlQauvzSq01ICe6zvm

    • Dridex

      Dridex(known as Bugat/Cridex) is a form of malware that specializes in stealing bank credentials.

    • Dridex Shellcode

      Detects Dridex Payload shellcode injected in Explorer process.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

System Information Discovery

1
T1082

Query Registry

1
T1012

Tasks