General

  • Target

    184ff73a94684953b217fdd594a4cc1f_JaffaCakes118

  • Size

    337KB

  • Sample

    240628-bzyvlstfpb

  • MD5

    184ff73a94684953b217fdd594a4cc1f

  • SHA1

    952155d9927433503dbdf3c2d1bb15f7460e779d

  • SHA256

    fb58ba6a44d5dd40a677b7da027011169ae9765c16e62743868c6e273612b6ce

  • SHA512

    04b1d3c0e2e522551814745273b43f2c71fb66639c3f2325192515e1fec0c2272ca7361c76891586980ef56114cb734eda3b3a7f1557772a54646167280f6d78

  • SSDEEP

    6144:PN0yr1sO/wIKS0FKtOT/OrDtgUi0uvQee7Qee/0QeesQeeglQeekQeeDC7M3HCR7:1G6wndYtamDSU1MHCRfl1

Malware Config

Targets

    • Target

      184ff73a94684953b217fdd594a4cc1f_JaffaCakes118

    • Size

      337KB

    • MD5

      184ff73a94684953b217fdd594a4cc1f

    • SHA1

      952155d9927433503dbdf3c2d1bb15f7460e779d

    • SHA256

      fb58ba6a44d5dd40a677b7da027011169ae9765c16e62743868c6e273612b6ce

    • SHA512

      04b1d3c0e2e522551814745273b43f2c71fb66639c3f2325192515e1fec0c2272ca7361c76891586980ef56114cb734eda3b3a7f1557772a54646167280f6d78

    • SSDEEP

      6144:PN0yr1sO/wIKS0FKtOT/OrDtgUi0uvQee7Qee/0QeesQeeglQeekQeeDC7M3HCR7:1G6wndYtamDSU1MHCRfl1

    • Modifies WinLogon for persistence

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Tasks