General

  • Target

    19a4255837768deb829292292e02ab98_JaffaCakes118

  • Size

    214KB

  • Sample

    240628-lja4qavfnq

  • MD5

    19a4255837768deb829292292e02ab98

  • SHA1

    0a460aa0774f3d508856b7936f793051c14cecf5

  • SHA256

    0e631e8ab2131938486c4ae8e2880790ea0f232cf837dd90c5507500986cb16b

  • SHA512

    293a8065991cf27c1387351412ef01e59e3e9fbed87f3564a1172e04db006c429aad3f0e40249f1920a9a4414ffe2166932c0cd364c4734451b996251180ffe8

  • SSDEEP

    3072:2ttEE8okQqIKA0cP/fAndU+hs7Uw4zt3dj9Q2eYCtNONVrb0mHl2fbvCJ7s7qn:gE9otjnD+ZwQfGfEb0k2jv

Score
10/10

Malware Config

Targets

    • Target

      19a4255837768deb829292292e02ab98_JaffaCakes118

    • Size

      214KB

    • MD5

      19a4255837768deb829292292e02ab98

    • SHA1

      0a460aa0774f3d508856b7936f793051c14cecf5

    • SHA256

      0e631e8ab2131938486c4ae8e2880790ea0f232cf837dd90c5507500986cb16b

    • SHA512

      293a8065991cf27c1387351412ef01e59e3e9fbed87f3564a1172e04db006c429aad3f0e40249f1920a9a4414ffe2166932c0cd364c4734451b996251180ffe8

    • SSDEEP

      3072:2ttEE8okQqIKA0cP/fAndU+hs7Uw4zt3dj9Q2eYCtNONVrb0mHl2fbvCJ7s7qn:gE9otjnD+ZwQfGfEb0k2jv

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Uses the VBS compiler for execution

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scripting

1
T1064

Defense Evasion

Scripting

1
T1064

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks