General

  • Target

    0a9319f703bf6a53735f04958044e557_JaffaCakes118

  • Size

    108KB

  • Sample

    240624-yrsd7azhmg

  • MD5

    0a9319f703bf6a53735f04958044e557

  • SHA1

    54143a9c60eed4204cb3adb161e12d3c3b5550bc

  • SHA256

    be39e5680f06b8b03772e880ea622aa4a75ce381d13c8c285954c197281afe84

  • SHA512

    a5cc37d0676814cd0ec5138383e81baa4ec2cb7f459b7f05602a12f4ac36f8b6e503b364ba43245f2eb8db8ca79f67bf4cc20ea986e89887eac12d559fc70270

  • SSDEEP

    1536:jSXz96Wg+1yMC8nTAd/visDXWBiNLk6l2xyQFtVltJQCHCPjZ747Joxl:ibJpnTAd3iOmBiN46syQFtACibsS

Malware Config

Targets

    • Target

      0a9319f703bf6a53735f04958044e557_JaffaCakes118

    • Size

      108KB

    • MD5

      0a9319f703bf6a53735f04958044e557

    • SHA1

      54143a9c60eed4204cb3adb161e12d3c3b5550bc

    • SHA256

      be39e5680f06b8b03772e880ea622aa4a75ce381d13c8c285954c197281afe84

    • SHA512

      a5cc37d0676814cd0ec5138383e81baa4ec2cb7f459b7f05602a12f4ac36f8b6e503b364ba43245f2eb8db8ca79f67bf4cc20ea986e89887eac12d559fc70270

    • SSDEEP

      1536:jSXz96Wg+1yMC8nTAd/visDXWBiNLk6l2xyQFtVltJQCHCPjZ747Joxl:ibJpnTAd3iOmBiN46syQFtACibsS

    • Possible privilege escalation attempt

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Loads dropped DLL

    • Modifies file permissions

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • File and Directory Permissions Modification: Windows File and Directory Permissions Modification

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

File and Directory Permissions Modification

2
T1222

Windows File and Directory Permissions Modification

1
T1222.001

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Peripheral Device Discovery

1
T1120

Tasks