General
-
Target
19fb9afb30fe88d256fdcb2467833578_JaffaCakes118
-
Size
3.2MB
-
Sample
240628-ntlpbazgmr
-
MD5
19fb9afb30fe88d256fdcb2467833578
-
SHA1
438d3369da71184c31b226f5bf090c8954592ff2
-
SHA256
41e8a5c7267018eeff24f122ff2227e7b7ed2e3dc22338745df631d524502c13
-
SHA512
afa881d3600598f87ca6c34f809afe2107e55791dcbf1b59a7e4fa2be093a40423729d7f5a04e1db6748f45c7c5024d9421762996fd9d31edef915032f58d3a0
-
SSDEEP
24576:oFE//Tct4bOs8JVAzWT3G82PQlIYzuJBCWDlWwy018klgFaVSNucktoZAmK+vo11:aSVn
Behavioral task
behavioral1
Sample
19fb9afb30fe88d256fdcb2467833578_JaffaCakes118.exe
Resource
win7-20231129-en
Malware Config
Targets
-
-
Target
19fb9afb30fe88d256fdcb2467833578_JaffaCakes118
-
Size
3.2MB
-
MD5
19fb9afb30fe88d256fdcb2467833578
-
SHA1
438d3369da71184c31b226f5bf090c8954592ff2
-
SHA256
41e8a5c7267018eeff24f122ff2227e7b7ed2e3dc22338745df631d524502c13
-
SHA512
afa881d3600598f87ca6c34f809afe2107e55791dcbf1b59a7e4fa2be093a40423729d7f5a04e1db6748f45c7c5024d9421762996fd9d31edef915032f58d3a0
-
SSDEEP
24576:oFE//Tct4bOs8JVAzWT3G82PQlIYzuJBCWDlWwy018klgFaVSNucktoZAmK+vo11:aSVn
-
Modifies WinLogon for persistence
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-
Adds Run key to start application
-
AutoIT Executable
AutoIT scripts compiled to PE executables.
-
Drops file in System32 directory
-
MITRE ATT&CK Matrix ATT&CK v13
Persistence
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
1Winlogon Helper DLL
1Privilege Escalation
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
1Winlogon Helper DLL
1