General

  • Target

    00542b9d21af209948ad923d035e53fe_JaffaCakes118

  • Size

    2.3MB

  • Sample

    240622-abbjqsxakb

  • MD5

    00542b9d21af209948ad923d035e53fe

  • SHA1

    eeb88fcc92a58309dd26019052a7ae5bcfc02110

  • SHA256

    d7841d55e43d7bc435dadaae9997d975ed0001ab18fa4f7e4f2fce6a36105093

  • SHA512

    8a01d01f7bd7df1a7371cda7158c1e69dcc98d078af626eb47ac4f1cc7e78aa67008210ad850f4a1bfbcd4e1f2b39e3c669eb4425e8acb85ef97585d6169b69e

  • SSDEEP

    49152:tglKw04wX6NOzrqYFxZoZ3H0sm9NnlKGDMeXOIpaQqGcKX:tOK7lzOYF4JH03JKvuOqn

Malware Config

Targets

    • Target

      00542b9d21af209948ad923d035e53fe_JaffaCakes118

    • Size

      2.3MB

    • MD5

      00542b9d21af209948ad923d035e53fe

    • SHA1

      eeb88fcc92a58309dd26019052a7ae5bcfc02110

    • SHA256

      d7841d55e43d7bc435dadaae9997d975ed0001ab18fa4f7e4f2fce6a36105093

    • SHA512

      8a01d01f7bd7df1a7371cda7158c1e69dcc98d078af626eb47ac4f1cc7e78aa67008210ad850f4a1bfbcd4e1f2b39e3c669eb4425e8acb85ef97585d6169b69e

    • SSDEEP

      49152:tglKw04wX6NOzrqYFxZoZ3H0sm9NnlKGDMeXOIpaQqGcKX:tOK7lzOYF4JH03JKvuOqn

    • Disables service(s)

    • RMS

      Remote Manipulator System (RMS) is a remote access tool developed by Russian organization TektonIT.

    • Modifies Windows Firewall

    • Sets file to hidden

      Modifies file attributes to stop it showing in Explorer etc.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Execution

System Services

1
T1569

Service Execution

1
T1569.002

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Hide Artifacts

2
T1564

Hidden Files and Directories

2
T1564.001

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Impact

Service Stop

1
T1489

Tasks