General

  • Target

    19501fe7f5c62345c3f8c32adac47672_JaffaCakes118

  • Size

    740KB

  • Sample

    240628-jhbmra1brl

  • MD5

    19501fe7f5c62345c3f8c32adac47672

  • SHA1

    00af478335760f0d43f209bbe7fc4388a2102959

  • SHA256

    4ac0f7b35524f01616e97985c1ae523266554e29c9e442dcea3bf8449a5e1391

  • SHA512

    ade9dba54fe26c2ac5571fcb30bce6076e41a92c6e37569f871212ca0b0025a66274beae433e454c0f1a12b1c9a841e1e2c6fa2360bfcc656da9dec8336a2a93

  • SSDEEP

    12288:AnHEYPYJ6nX+X384FppaIXTUhfZcYQFttDuckX+vR5Lz5RD:UEB6nGPpzTUDQjtyckOLz5RD

Score
7/10

Malware Config

Targets

    • Target

      19501fe7f5c62345c3f8c32adac47672_JaffaCakes118

    • Size

      740KB

    • MD5

      19501fe7f5c62345c3f8c32adac47672

    • SHA1

      00af478335760f0d43f209bbe7fc4388a2102959

    • SHA256

      4ac0f7b35524f01616e97985c1ae523266554e29c9e442dcea3bf8449a5e1391

    • SHA512

      ade9dba54fe26c2ac5571fcb30bce6076e41a92c6e37569f871212ca0b0025a66274beae433e454c0f1a12b1c9a841e1e2c6fa2360bfcc656da9dec8336a2a93

    • SSDEEP

      12288:AnHEYPYJ6nX+X384FppaIXTUhfZcYQFttDuckX+vR5Lz5RD:UEB6nGPpzTUDQjtyckOLz5RD

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks