General

  • Target

    1cde43adb3042f3d8595113fbf71231d_JaffaCakes118

  • Size

    2.5MB

  • Sample

    240701-262syswbmb

  • MD5

    1cde43adb3042f3d8595113fbf71231d

  • SHA1

    8c1a554f07c813a11d2f6505224d2bad21f36360

  • SHA256

    16185f283af3fef1b2c0c576af0fa224332aa62b475f93d7b906e50a0cbb1fe8

  • SHA512

    b1ac0a68c5bf2bd718a584d09f638339b264cf96b895dadbe693757432f613862b22b087eefdd3976fc0b1ba42626012f26bba293f16e273969769526cbc8f71

  • SSDEEP

    49152:dnUu7j8ixe5V1HrI9HElzSdsIMiSwPN+fYh/YMPf8:dD7l85jrI9H8GdcwPcwtdf

Score
7/10

Malware Config

Targets

    • Target

      1cde43adb3042f3d8595113fbf71231d_JaffaCakes118

    • Size

      2.5MB

    • MD5

      1cde43adb3042f3d8595113fbf71231d

    • SHA1

      8c1a554f07c813a11d2f6505224d2bad21f36360

    • SHA256

      16185f283af3fef1b2c0c576af0fa224332aa62b475f93d7b906e50a0cbb1fe8

    • SHA512

      b1ac0a68c5bf2bd718a584d09f638339b264cf96b895dadbe693757432f613862b22b087eefdd3976fc0b1ba42626012f26bba293f16e273969769526cbc8f71

    • SSDEEP

      49152:dnUu7j8ixe5V1HrI9HElzSdsIMiSwPN+fYh/YMPf8:dD7l85jrI9H8GdcwPcwtdf

    Score
    7/10
    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Tasks