Analysis

  • max time kernel
    147s
  • max time network
    150s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    20-06-2024 02:40

General

  • Target

    021cdb850fe09593d45b048ae3196acc_JaffaCakes118.exe

  • Size

    655KB

  • MD5

    021cdb850fe09593d45b048ae3196acc

  • SHA1

    b591a65f0957b17f975def85b65f7e50f89768d3

  • SHA256

    87b06830e0b34bdf03603b903ab48c890582bf47bc8cc1704206159d951834e2

  • SHA512

    465063897c25616e33a4853eed628fa5e7cb7b0e4ccdfae9d2aa64665d03d2409ec6b4954e2c21c3454dba889cc254d66867c329a45078ef1beb3891ff5d1571

  • SSDEEP

    12288:g9DN9uW1XeqFYDeA/pSuk7fMo5Td5DUhj/5clKKQ17NiPcc4h9YX0:ghvuW19juzKlKKG7kPUV

Score
7/10

Malware Config

Signatures

  • Identifies Wine through registry keys 2 TTPs 1 IoCs

    Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

Processes

  • C:\Users\Admin\AppData\Local\Temp\021cdb850fe09593d45b048ae3196acc_JaffaCakes118.exe
    "C:\Users\Admin\AppData\Local\Temp\021cdb850fe09593d45b048ae3196acc_JaffaCakes118.exe"
    1⤵
    • Identifies Wine through registry keys
    PID:2468

Network

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/2468-0-0x0000000000400000-0x00000000005CA000-memory.dmp
    Filesize

    1.8MB

  • memory/2468-1-0x0000000000400000-0x00000000005CA000-memory.dmp
    Filesize

    1.8MB