General

  • Target

    1a54e0b5a1cd029de96d226a8ef57f49_JaffaCakes118

  • Size

    43KB

  • Sample

    240628-qydklsvfmp

  • MD5

    1a54e0b5a1cd029de96d226a8ef57f49

  • SHA1

    c4c007dd955c0cdd377037625355d4fb078166d9

  • SHA256

    d31a5d72e83043ee452b13eaaac8bea7dfd2a8800fcc9f57153c155c45df8671

  • SHA512

    a016d0d4d1c564c76430061cc5b697934df1797f7c7ee0a6db26f0f2f6e1ca4aaea014a9a70881e1aee97bfe945f69e162751fd6307fc635acc9b2b64fe11c12

  • SSDEEP

    768:+YY4jCR2J2dTVmQDauctW085lTZXfxkVRvSxcZfqBT5M2OxO48BGRliYsBYJj91G:zY4+R2J+mQW5t7YR8RvSxcZfaT5M2RBB

Malware Config

Targets

    • Target

      1a54e0b5a1cd029de96d226a8ef57f49_JaffaCakes118

    • Size

      43KB

    • MD5

      1a54e0b5a1cd029de96d226a8ef57f49

    • SHA1

      c4c007dd955c0cdd377037625355d4fb078166d9

    • SHA256

      d31a5d72e83043ee452b13eaaac8bea7dfd2a8800fcc9f57153c155c45df8671

    • SHA512

      a016d0d4d1c564c76430061cc5b697934df1797f7c7ee0a6db26f0f2f6e1ca4aaea014a9a70881e1aee97bfe945f69e162751fd6307fc635acc9b2b64fe11c12

    • SSDEEP

      768:+YY4jCR2J2dTVmQDauctW085lTZXfxkVRvSxcZfqBT5M2OxO48BGRliYsBYJj91G:zY4+R2J+mQW5t7YR8RvSxcZfaT5M2RBB

    • Modifies firewall policy service

    • Impair Defenses: Safe Mode Boot

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Browser Extensions

1
T1176

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

3
T1112

Impair Defenses

2
T1562

Disable or Modify System Firewall

1
T1562.004

Safe Mode Boot

1
T1562.009

Tasks