General

  • Target

    153807fd4ed81e99387e80b6d12ddef3_JaffaCakes118

  • Size

    163KB

  • Sample

    240627-jqjnbssdlj

  • MD5

    153807fd4ed81e99387e80b6d12ddef3

  • SHA1

    2926c65bee567241abd703f7d3434942faec57b7

  • SHA256

    2801f320eb2fc6005be000a31225eb6f2e33bbb6e42f99897003b800ec38eb72

  • SHA512

    074c7c165f2c86dd96a86f0e7cd1af2f545c08c13012aa809fe511dc2a3a093978c846e721cce3c2d1d65135b5947df9685ac97ccf1be1c42c9842508845c3cc

  • SSDEEP

    3072:gv5lmIoUsJiRvjAZrrF7EJXBPCisvrbviOkAgJQj9j:gxnoULRvEVlEvAvP1KQ

Malware Config

Extracted

Family

metasploit

Version

encoder/call4_dword_xor

Targets

    • Target

      153807fd4ed81e99387e80b6d12ddef3_JaffaCakes118

    • Size

      163KB

    • MD5

      153807fd4ed81e99387e80b6d12ddef3

    • SHA1

      2926c65bee567241abd703f7d3434942faec57b7

    • SHA256

      2801f320eb2fc6005be000a31225eb6f2e33bbb6e42f99897003b800ec38eb72

    • SHA512

      074c7c165f2c86dd96a86f0e7cd1af2f545c08c13012aa809fe511dc2a3a093978c846e721cce3c2d1d65135b5947df9685ac97ccf1be1c42c9842508845c3cc

    • SSDEEP

      3072:gv5lmIoUsJiRvjAZrrF7EJXBPCisvrbviOkAgJQj9j:gxnoULRvEVlEvAvP1KQ

    • MetaSploit

      Detected malicious payload which is part of the Metasploit Framework, likely generated with msfvenom or similar.

    • Modifies firewall policy service

    • Windows security bypass

    • Modifies Windows Firewall

    • Deletes itself

    • Executes dropped EXE

    • Windows security modification

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Modify Registry

3
T1112

Impair Defenses

4
T1562

Disable or Modify Tools

2
T1562.001

Disable or Modify System Firewall

2
T1562.004

Discovery

System Information Discovery

1
T1082

Tasks