General

  • Target

    1a707048a67b017c6541fbd6890b7c44_JaffaCakes118

  • Size

    52KB

  • Sample

    240628-rlahvsterg

  • MD5

    1a707048a67b017c6541fbd6890b7c44

  • SHA1

    933f0881e402213bea35605041bb768c90c115e8

  • SHA256

    0e78392e4df9088e12d3c3a604f8ea936631aaa5b6b40372cecaaad38140bda1

  • SHA512

    22b41bedee5cf62acd4552f88c37dc835615fbb1e0a84800eb361a2d160cbd2458e204a7badacb7aea9f94f783da6535d77bc5b1ac6102343ae33e35ab771dfe

  • SSDEEP

    768:VLi0NnqrjIcGA+9H5MQO7BUdLOyOLm/Cb5vTOc74Hpyfogpty2uhNqFeTCjC0b4:ViHIcz+j0W2QA5v974JyZuCv2

Malware Config

Targets

    • Target

      1a707048a67b017c6541fbd6890b7c44_JaffaCakes118

    • Size

      52KB

    • MD5

      1a707048a67b017c6541fbd6890b7c44

    • SHA1

      933f0881e402213bea35605041bb768c90c115e8

    • SHA256

      0e78392e4df9088e12d3c3a604f8ea936631aaa5b6b40372cecaaad38140bda1

    • SHA512

      22b41bedee5cf62acd4552f88c37dc835615fbb1e0a84800eb361a2d160cbd2458e204a7badacb7aea9f94f783da6535d77bc5b1ac6102343ae33e35ab771dfe

    • SSDEEP

      768:VLi0NnqrjIcGA+9H5MQO7BUdLOyOLm/Cb5vTOc74Hpyfogpty2uhNqFeTCjC0b4:ViHIcz+j0W2QA5v974JyZuCv2

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Checks whether UAC is enabled

    • Drops desktop.ini file(s)

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

3
T1082

Tasks