General

  • Target

    1a274bfc61dbc5d56cd0c2b759491384_JaffaCakes118

  • Size

    128KB

  • Sample

    240628-pwkqgasfrm

  • MD5

    1a274bfc61dbc5d56cd0c2b759491384

  • SHA1

    63b8c964c56aff894f806a6c1bedc34ccd534582

  • SHA256

    62a630c61232f113743d1926abef5e67adbd508cd693a384993e89f6828613f9

  • SHA512

    263c19616281e2a9c7a11bc6bac44a228ba4755da780439de63607a7bd269657f397db259620254df2b81171392efd728a26eaaeb53a5a14b915fa02fcea11c7

  • SSDEEP

    3072:EmeDmBqskJ3U8SmcmfhGwycxXUYU3owUK0tatXI+dJ:E82UrmPB9UYU3o9JEt9

Malware Config

Targets

    • Target

      1a274bfc61dbc5d56cd0c2b759491384_JaffaCakes118

    • Size

      128KB

    • MD5

      1a274bfc61dbc5d56cd0c2b759491384

    • SHA1

      63b8c964c56aff894f806a6c1bedc34ccd534582

    • SHA256

      62a630c61232f113743d1926abef5e67adbd508cd693a384993e89f6828613f9

    • SHA512

      263c19616281e2a9c7a11bc6bac44a228ba4755da780439de63607a7bd269657f397db259620254df2b81171392efd728a26eaaeb53a5a14b915fa02fcea11c7

    • SSDEEP

      3072:EmeDmBqskJ3U8SmcmfhGwycxXUYU3owUK0tatXI+dJ:E82UrmPB9UYU3o9JEt9

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks