General

  • Target

    1a706d5383c7092d51ca8e7f12530649_JaffaCakes118

  • Size

    659KB

  • Sample

    240628-rk8z2awhpn

  • MD5

    1a706d5383c7092d51ca8e7f12530649

  • SHA1

    4aa83450fdc8e594697ea541518949c2a04bb7b0

  • SHA256

    81d522b210d792d32e3d44735e3c7c39a57eae172f5520fa4b55ed1007efdea0

  • SHA512

    406626bb597e60325fcd168eeaca763b27cf7bd206ecf3cc2a253d54a80934d0b10616a3cb92fd67c91bfa04417ede23c07054f0d3a8d87f210cc5d958330cf4

  • SSDEEP

    12288:d5RdOR3PHKhGLxe0DA8PSTRK8AYHv1L8qKtZTln7NEakAR8+JU/w:H3OR3PHKux7DA8PMfrHUtZhnxEa9R8tY

Malware Config

Targets

    • Target

      1a706d5383c7092d51ca8e7f12530649_JaffaCakes118

    • Size

      659KB

    • MD5

      1a706d5383c7092d51ca8e7f12530649

    • SHA1

      4aa83450fdc8e594697ea541518949c2a04bb7b0

    • SHA256

      81d522b210d792d32e3d44735e3c7c39a57eae172f5520fa4b55ed1007efdea0

    • SHA512

      406626bb597e60325fcd168eeaca763b27cf7bd206ecf3cc2a253d54a80934d0b10616a3cb92fd67c91bfa04417ede23c07054f0d3a8d87f210cc5d958330cf4

    • SSDEEP

      12288:d5RdOR3PHKhGLxe0DA8PSTRK8AYHv1L8qKtZTln7NEakAR8+JU/w:H3OR3PHKux7DA8PMfrHUtZhnxEa9R8tY

    • Server Software Component: Terminal Services DLL

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks