General

  • Target

    15a67ca8c2374635659a6c6a0de2e862_JaffaCakes118

  • Size

    193KB

  • Sample

    240627-mgmv6syfrp

  • MD5

    15a67ca8c2374635659a6c6a0de2e862

  • SHA1

    2e9c7e3aeae2ed52e3585fe019cc48136443b44d

  • SHA256

    b2e8e2958872fca322b9e8cc0cd3e95b29cab03032bdc72816bf37bb21a6118d

  • SHA512

    5f742205652eb541fbc72c06d96260799745a442cdb1d310bb91fd887f389992e784ac56aaacf94045a687a66fa515f51eb768ff0c6bdf30b97b9ebccfbb0216

  • SSDEEP

    3072:s73MITL/9oSmkbx3ZtffjBTnIwanLMy7L/k6YpQAz8Wnr:6dTpountf75Iwkh7o6BQnr

Malware Config

Targets

    • Target

      15a67ca8c2374635659a6c6a0de2e862_JaffaCakes118

    • Size

      193KB

    • MD5

      15a67ca8c2374635659a6c6a0de2e862

    • SHA1

      2e9c7e3aeae2ed52e3585fe019cc48136443b44d

    • SHA256

      b2e8e2958872fca322b9e8cc0cd3e95b29cab03032bdc72816bf37bb21a6118d

    • SHA512

      5f742205652eb541fbc72c06d96260799745a442cdb1d310bb91fd887f389992e784ac56aaacf94045a687a66fa515f51eb768ff0c6bdf30b97b9ebccfbb0216

    • SSDEEP

      3072:s73MITL/9oSmkbx3ZtffjBTnIwanLMy7L/k6YpQAz8Wnr:6dTpountf75Iwkh7o6BQnr

    • Modifies WinLogon for persistence

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Tasks