General

  • Target

    1a6bebbb4f4c7766b1da6ca32433df40_JaffaCakes118

  • Size

    463KB

  • Sample

    240628-rgdpqawfqq

  • MD5

    1a6bebbb4f4c7766b1da6ca32433df40

  • SHA1

    ea676e005d47caad5d0f49efbf99f450da578201

  • SHA256

    3c52bdf812310190cec125a018673269e83708be08d49abd3897b536aef3dae6

  • SHA512

    39136d8c2c29687915059b37c1b2e54c3c67586f6255e0176fd2d6adb4ed05ca2091677c4ea8b6504d0ab9330168f6d1ac57477d1a2c021e571d27ed82b77bea

  • SSDEEP

    6144:S+GsMYod+X3oI+YO/sMYod+X3oI+Y1sMYod+X3oI+YLsMYod+X3oI+YC:dk5d+X3sD5d+X375d+X315d+X3I

Malware Config

Targets

    • Target

      1a6bebbb4f4c7766b1da6ca32433df40_JaffaCakes118

    • Size

      463KB

    • MD5

      1a6bebbb4f4c7766b1da6ca32433df40

    • SHA1

      ea676e005d47caad5d0f49efbf99f450da578201

    • SHA256

      3c52bdf812310190cec125a018673269e83708be08d49abd3897b536aef3dae6

    • SHA512

      39136d8c2c29687915059b37c1b2e54c3c67586f6255e0176fd2d6adb4ed05ca2091677c4ea8b6504d0ab9330168f6d1ac57477d1a2c021e571d27ed82b77bea

    • SSDEEP

      6144:S+GsMYod+X3oI+YO/sMYod+X3oI+Y1sMYod+X3oI+YLsMYod+X3oI+YC:dk5d+X3sD5d+X375d+X315d+X3I

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks