General

  • Target

    154dd7d9638995072c2c78ab478a3043_JaffaCakes118

  • Size

    166KB

  • Sample

    240627-j9bf3atcpl

  • MD5

    154dd7d9638995072c2c78ab478a3043

  • SHA1

    339ecc8ec888de71c6f76913e8cc97a0dcbc0060

  • SHA256

    9fcc3b77d2085e60800e7f6e61e87d494c5b9bab5903135230f21b24df4aa67d

  • SHA512

    663349206cbef3ee2b8f0a29fb89db78bf9cc8a319c910bd73e993b2a7cc21924402c156096b15467017aabb7f315e5f3adf75d6bba1cd7b60adafd4e5bb4d2b

  • SSDEEP

    1536:8NpbWTono2PF9yJH9KBjH7ZoSQoL+Qz6AkMK6TNXkZXdrBVPjlVRuwz24+g:ldKFOoL16AkMK6BXEtrB9jlP5Yg

Malware Config

Targets

    • Target

      154dd7d9638995072c2c78ab478a3043_JaffaCakes118

    • Size

      166KB

    • MD5

      154dd7d9638995072c2c78ab478a3043

    • SHA1

      339ecc8ec888de71c6f76913e8cc97a0dcbc0060

    • SHA256

      9fcc3b77d2085e60800e7f6e61e87d494c5b9bab5903135230f21b24df4aa67d

    • SHA512

      663349206cbef3ee2b8f0a29fb89db78bf9cc8a319c910bd73e993b2a7cc21924402c156096b15467017aabb7f315e5f3adf75d6bba1cd7b60adafd4e5bb4d2b

    • SSDEEP

      1536:8NpbWTono2PF9yJH9KBjH7ZoSQoL+Qz6AkMK6TNXkZXdrBVPjlVRuwz24+g:ldKFOoL16AkMK6BXEtrB9jlP5Yg

    • Modifies WinLogon for persistence

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Tasks