General

  • Target

    13f17e5ad6d8c22c18ab112aaeb12c50_JaffaCakes118

  • Size

    256KB

  • Sample

    240701-je8s3szalh

  • MD5

    13f17e5ad6d8c22c18ab112aaeb12c50

  • SHA1

    67f75eee7a02131b1931974153deede8b66ee10b

  • SHA256

    3af16abac9f7914165cbb63081a0c5b7d5f37957602ff8c0d51f02c7300864f4

  • SHA512

    8e7e712d9f17ef33ee1d1b742f73fec9d0de2b27d84bab71f8722ee00e869842a4e34eae328c7dbaec836be8746d72c9bc5e7c1b262829e5c75f32097c089d6b

  • SSDEEP

    6144:MLDB4bRUpbFqRFPK7iKce5DljP6U2DPjHTKF:SSAbFCJQTcyb6THTKF

Malware Config

Targets

    • Target

      13f17e5ad6d8c22c18ab112aaeb12c50_JaffaCakes118

    • Size

      256KB

    • MD5

      13f17e5ad6d8c22c18ab112aaeb12c50

    • SHA1

      67f75eee7a02131b1931974153deede8b66ee10b

    • SHA256

      3af16abac9f7914165cbb63081a0c5b7d5f37957602ff8c0d51f02c7300864f4

    • SHA512

      8e7e712d9f17ef33ee1d1b742f73fec9d0de2b27d84bab71f8722ee00e869842a4e34eae328c7dbaec836be8746d72c9bc5e7c1b262829e5c75f32097c089d6b

    • SSDEEP

      6144:MLDB4bRUpbFqRFPK7iKce5DljP6U2DPjHTKF:SSAbFCJQTcyb6THTKF

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Tasks