General

  • Target

    bce55d9856da631b5c069b00005bb44a_JaffaCakes118

  • Size

    536KB

  • Sample

    240618-tz19vavhrm

  • MD5

    bce55d9856da631b5c069b00005bb44a

  • SHA1

    51ee1bd68d8ec67ef245d0a60c403dd97fe9ae14

  • SHA256

    39bc96e86d7a6502c310e06825180c299a70128bb8eaa94ef7e5a0025342782d

  • SHA512

    b43b1aeade497a11958abb90f5f751ebd743b1fc8b440cb1f36311f03c322d5c2e12e45568ac55e42809b2ec245e1e48094a69679e884c3ecb5acb4be9914715

  • SSDEEP

    12288:dGyp/J7n7QUVcZDcaWcH9JfQ8AB7dneH0smaLDwDdJmAOT:dGyv5V5WXfxAWBmeDwD1OT

Malware Config

Targets

    • Target

      bce55d9856da631b5c069b00005bb44a_JaffaCakes118

    • Size

      536KB

    • MD5

      bce55d9856da631b5c069b00005bb44a

    • SHA1

      51ee1bd68d8ec67ef245d0a60c403dd97fe9ae14

    • SHA256

      39bc96e86d7a6502c310e06825180c299a70128bb8eaa94ef7e5a0025342782d

    • SHA512

      b43b1aeade497a11958abb90f5f751ebd743b1fc8b440cb1f36311f03c322d5c2e12e45568ac55e42809b2ec245e1e48094a69679e884c3ecb5acb4be9914715

    • SSDEEP

      12288:dGyp/J7n7QUVcZDcaWcH9JfQ8AB7dneH0smaLDwDdJmAOT:dGyv5V5WXfxAWBmeDwD1OT

    • AdWind

      A Java-based RAT family operated as malware-as-a-service.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

2
T1112

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Tasks