General

  • Target

    190780b1b9f1633b470168a18e5c9d55_JaffaCakes118

  • Size

    740KB

  • Sample

    240628-gmqw5avaqa

  • MD5

    190780b1b9f1633b470168a18e5c9d55

  • SHA1

    336d1fe7a8cc69e7b6a0b54a2046375d670a1ef5

  • SHA256

    d139bc774c574f95567e0f22d3089cba491e3bf8506d8eaf978383954d696c3b

  • SHA512

    c7e3712afc0910be3e987173839f491d9657f850fa1cf8f99233151decfa8662e51550f923f0bd82079baa68d37bf840f066f8d1e48466612d97c7eea5cd0497

  • SSDEEP

    12288:AnHEYPYJ6nX+X384FppaIXTUhfZcYQFttDuckX+vR5Lz5RS:UEB6nGPpzTUDQjtyckOLz5RS

Score
7/10

Malware Config

Targets

    • Target

      190780b1b9f1633b470168a18e5c9d55_JaffaCakes118

    • Size

      740KB

    • MD5

      190780b1b9f1633b470168a18e5c9d55

    • SHA1

      336d1fe7a8cc69e7b6a0b54a2046375d670a1ef5

    • SHA256

      d139bc774c574f95567e0f22d3089cba491e3bf8506d8eaf978383954d696c3b

    • SHA512

      c7e3712afc0910be3e987173839f491d9657f850fa1cf8f99233151decfa8662e51550f923f0bd82079baa68d37bf840f066f8d1e48466612d97c7eea5cd0497

    • SSDEEP

      12288:AnHEYPYJ6nX+X384FppaIXTUhfZcYQFttDuckX+vR5Lz5RS:UEB6nGPpzTUDQjtyckOLz5RS

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks