General

  • Target

    192e139015c44fbc67b75a89abe99a86_JaffaCakes118

  • Size

    166KB

  • Sample

    240628-hmepjaygnr

  • MD5

    192e139015c44fbc67b75a89abe99a86

  • SHA1

    15599b909247601fbb064a7c27c8151aae1d6a6c

  • SHA256

    7c547ff815f4f818f2f52ce61ecbfc00131167990209ff21c4a224888455fea6

  • SHA512

    879e617162390934c36d513936615171a8f99f9ca4ea922420779e33a4f8fe22f6f4da5eb2f2410940fa16fbadcec4ddef8f3549bcb5b1b06fef0994fa833f50

  • SSDEEP

    1536:5NpbWTono2PF9yJH9KBjH7ZoSQoL+Qz6AdvaLj30b9KVv6q7pbhD3fdaAsU3wNBz:wdKFOoL16Ady330wN6qb3MAxwgKaM

Malware Config

Targets

    • Target

      192e139015c44fbc67b75a89abe99a86_JaffaCakes118

    • Size

      166KB

    • MD5

      192e139015c44fbc67b75a89abe99a86

    • SHA1

      15599b909247601fbb064a7c27c8151aae1d6a6c

    • SHA256

      7c547ff815f4f818f2f52ce61ecbfc00131167990209ff21c4a224888455fea6

    • SHA512

      879e617162390934c36d513936615171a8f99f9ca4ea922420779e33a4f8fe22f6f4da5eb2f2410940fa16fbadcec4ddef8f3549bcb5b1b06fef0994fa833f50

    • SSDEEP

      1536:5NpbWTono2PF9yJH9KBjH7ZoSQoL+Qz6AdvaLj30b9KVv6q7pbhD3fdaAsU3wNBz:wdKFOoL16Ady330wN6qb3MAxwgKaM

    • Modifies WinLogon for persistence

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Tasks