General

  • Target

    1a4e0616d3bb6faaae67c2b9655b3691_JaffaCakes118

  • Size

    792KB

  • Sample

    240628-qr8geasbjb

  • MD5

    1a4e0616d3bb6faaae67c2b9655b3691

  • SHA1

    1063f0d26a161d91dec14755a65862be23f4d011

  • SHA256

    86584928126b210987919b533525f52937b87a2877130a39d456a37ccb9ee828

  • SHA512

    5d76bd1801a66e51d326aabc15e7fb3464590726101e72789917d287b1c5eb1afe48c4be5933f46091f555e5b7f918cb164eabfba77a131af2c92e37e3402c58

  • SSDEEP

    12288:FEnnhoUxDJKzPNZeO+2HBtIEMt/4FylEQKvC9ss+jJwdmDHif/uuhbJ2XyiCyai:JQaZx+2jIE0/jGgPghTspJ2kyn

Malware Config

Extracted

Family

sality

C2

http://89.119.67.154/testo5/

http://kukutrustnet777.info/home.gif

http://kukutrustnet888.info/home.gif

http://kukutrustnet987.info/home.gif

Targets

    • Target

      1a4e0616d3bb6faaae67c2b9655b3691_JaffaCakes118

    • Size

      792KB

    • MD5

      1a4e0616d3bb6faaae67c2b9655b3691

    • SHA1

      1063f0d26a161d91dec14755a65862be23f4d011

    • SHA256

      86584928126b210987919b533525f52937b87a2877130a39d456a37ccb9ee828

    • SHA512

      5d76bd1801a66e51d326aabc15e7fb3464590726101e72789917d287b1c5eb1afe48c4be5933f46091f555e5b7f918cb164eabfba77a131af2c92e37e3402c58

    • SSDEEP

      12288:FEnnhoUxDJKzPNZeO+2HBtIEMt/4FylEQKvC9ss+jJwdmDHif/uuhbJ2XyiCyai:JQaZx+2jIE0/jGgPghTspJ2kyn

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Create or Modify System Process

2
T1543

Windows Service

2
T1543.003

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Modify Registry

4
T1112

Impair Defenses

3
T1562

Disable or Modify Tools

1
T1562.001

Disable or Modify System Firewall

2
T1562.004

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Discovery

System Information Discovery

1
T1082

Tasks