General

  • Target

    18db4def8cf842a587434c88a510ff5c_JaffaCakes118

  • Size

    125KB

  • Sample

    240628-flypxasdnd

  • MD5

    18db4def8cf842a587434c88a510ff5c

  • SHA1

    8f07103541ae2a31155aa30ded4e095fac9d4f86

  • SHA256

    951ef36043f2a9addaf729c12f13a4a54b3f05f7920bd6355baee812a180834e

  • SHA512

    3822e009094340f3d2ce0395ec4ef617eb3a84d0f67c5c68fc19a96717262f92ee6e678b3a8857a05e6ba37a226f05eba3efbec207f3d9501dd3ffad91280259

  • SSDEEP

    3072:5gKMVt2OKlYXRNJgFvpRRUULR6pgHk+CR2F7swhTQrgFG:qz6GRP4BRRUULR6pgHBgrgFG

Malware Config

Targets

    • Target

      18db4def8cf842a587434c88a510ff5c_JaffaCakes118

    • Size

      125KB

    • MD5

      18db4def8cf842a587434c88a510ff5c

    • SHA1

      8f07103541ae2a31155aa30ded4e095fac9d4f86

    • SHA256

      951ef36043f2a9addaf729c12f13a4a54b3f05f7920bd6355baee812a180834e

    • SHA512

      3822e009094340f3d2ce0395ec4ef617eb3a84d0f67c5c68fc19a96717262f92ee6e678b3a8857a05e6ba37a226f05eba3efbec207f3d9501dd3ffad91280259

    • SSDEEP

      3072:5gKMVt2OKlYXRNJgFvpRRUULR6pgHk+CR2F7swhTQrgFG:qz6GRP4BRRUULR6pgHBgrgFG

    • Server Software Component: Terminal Services DLL

    • Deletes itself

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Tasks