General

  • Target

    1ce39d8fd3fd2abf9243410d2b13535d_JaffaCakes118

  • Size

    1.2MB

  • Sample

    240701-299yqszcpl

  • MD5

    1ce39d8fd3fd2abf9243410d2b13535d

  • SHA1

    435c89c070e130715a9301fc95ade7e110e61007

  • SHA256

    22668a4c0d13f3a84760c6db1d073806364734ac1520a86493065dbcc8afb03e

  • SHA512

    907278169d4cec7d637ed3c2c3ddc67c98f85f8db5427f4e974f7cb996acb4792d53b17985755a3d976d24b1e829db691fd2531fb5fed56e51d104caf13f1a5c

  • SSDEEP

    24576:u0iTG4yuM1MvmK4XCUOdQ2dq/kx+G8oYxh+xkGmVSRIU0lXEZQZuwRnr4LE2:unG496uOgQjhG8ZxVSRHa0QkwA

Malware Config

Targets

    • Target

      1ce39d8fd3fd2abf9243410d2b13535d_JaffaCakes118

    • Size

      1.2MB

    • MD5

      1ce39d8fd3fd2abf9243410d2b13535d

    • SHA1

      435c89c070e130715a9301fc95ade7e110e61007

    • SHA256

      22668a4c0d13f3a84760c6db1d073806364734ac1520a86493065dbcc8afb03e

    • SHA512

      907278169d4cec7d637ed3c2c3ddc67c98f85f8db5427f4e974f7cb996acb4792d53b17985755a3d976d24b1e829db691fd2531fb5fed56e51d104caf13f1a5c

    • SSDEEP

      24576:u0iTG4yuM1MvmK4XCUOdQ2dq/kx+G8oYxh+xkGmVSRIU0lXEZQZuwRnr4LE2:unG496uOgQjhG8ZxVSRHa0QkwA

    • Boot or Logon Autostart Execution: Active Setup

      Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.

    • ASPack v2.12-2.42

      Detects executables packed with ASPack v2.12-2.42

    • Deletes itself

    • Executes dropped EXE

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Active Setup

1
T1547.014

Privilege Escalation

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Active Setup

1
T1547.014

Defense Evasion

Modify Registry

3
T1112

Discovery

System Information Discovery

1
T1082

Tasks