General

  • Target

    187cbbb551217eedb4de9bcd3fe4dfdf_JaffaCakes118

  • Size

    243KB

  • Sample

    240628-c43j2azbjp

  • MD5

    187cbbb551217eedb4de9bcd3fe4dfdf

  • SHA1

    febbefb96025b33d1f297d1667e4721076bfcf0b

  • SHA256

    da7a728eb05ab3dbb399e48b3a187fe56cead389e2d497f980563d5a796f845e

  • SHA512

    98c69ef23d600f72a1d864732a535e186aa27b4792cf64fa019103fa7d95e0805001105e04321f205167deaca9e8a0f5c27ca28a2cd9802854d5dbdb2158f628

  • SSDEEP

    6144:PJ0ewPe2GJee75ovMOp9XUZg1fPgl96mLtAX:WHWf7+vMs9XUZKol96mS

Score
7/10

Malware Config

Targets

    • Target

      187cbbb551217eedb4de9bcd3fe4dfdf_JaffaCakes118

    • Size

      243KB

    • MD5

      187cbbb551217eedb4de9bcd3fe4dfdf

    • SHA1

      febbefb96025b33d1f297d1667e4721076bfcf0b

    • SHA256

      da7a728eb05ab3dbb399e48b3a187fe56cead389e2d497f980563d5a796f845e

    • SHA512

      98c69ef23d600f72a1d864732a535e186aa27b4792cf64fa019103fa7d95e0805001105e04321f205167deaca9e8a0f5c27ca28a2cd9802854d5dbdb2158f628

    • SSDEEP

      6144:PJ0ewPe2GJee75ovMOp9XUZg1fPgl96mLtAX:WHWf7+vMs9XUZKol96mS

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks