General

  • Target

    1918a56e59c6fc0ef416c70d12a41066_JaffaCakes118

  • Size

    89KB

  • Sample

    240628-g4zklaxhkp

  • MD5

    1918a56e59c6fc0ef416c70d12a41066

  • SHA1

    ab0ce8ca2dc1f2ff513184d6b125db2a0bdd996e

  • SHA256

    3a69b8f8242cfdbfb8821b227bedfc06cd6ed0241a21ff22299ebeb46fdcdaf6

  • SHA512

    798be97f94fada43c5c438205de5dcf570d682906856a5fc0591546263c1af45a368c16ee8bf2ad977b8f8edc5fa5b81c83191f3768acf25d4a303f1ee1a9dcd

  • SSDEEP

    1536:fzmGHl33AypA361pAN445Lslg1oTWlyrkR6WaUCyzwIG70XRCylYUXn0+rj:f6GHlnAZkpAN445Lslg1oEy4RXaUCmwE

Malware Config

Extracted

Family

metasploit

Version

encoder/call4_dword_xor

Targets

    • Target

      1918a56e59c6fc0ef416c70d12a41066_JaffaCakes118

    • Size

      89KB

    • MD5

      1918a56e59c6fc0ef416c70d12a41066

    • SHA1

      ab0ce8ca2dc1f2ff513184d6b125db2a0bdd996e

    • SHA256

      3a69b8f8242cfdbfb8821b227bedfc06cd6ed0241a21ff22299ebeb46fdcdaf6

    • SHA512

      798be97f94fada43c5c438205de5dcf570d682906856a5fc0591546263c1af45a368c16ee8bf2ad977b8f8edc5fa5b81c83191f3768acf25d4a303f1ee1a9dcd

    • SSDEEP

      1536:fzmGHl33AypA361pAN445Lslg1oTWlyrkR6WaUCyzwIG70XRCylYUXn0+rj:f6GHlnAZkpAN445Lslg1oEy4RXaUCmwE

    • MetaSploit

      Detected malicious payload which is part of the Metasploit Framework, likely generated with msfvenom or similar.

    • Modifies firewall policy service

    • Windows security bypass

    • Modifies Windows Firewall

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Windows security modification

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Modify Registry

3
T1112

Impair Defenses

4
T1562

Disable or Modify Tools

2
T1562.001

Disable or Modify System Firewall

2
T1562.004

Discovery

System Information Discovery

1
T1082

Tasks