General

  • Target

    13f1e732aafb6b1be1aee5d5fe03ca11_JaffaCakes118

  • Size

    384KB

  • Sample

    240701-jfml8szamg

  • MD5

    13f1e732aafb6b1be1aee5d5fe03ca11

  • SHA1

    284aeaffac85eb583d53b3cff2b950361c5aa1a4

  • SHA256

    939a18217e9f353396fe233dfd742a872b6c1ec265313795d74e238d294cc7ad

  • SHA512

    866c3c30bdee0380394d1b8eaa2673f9c226552427eed2b8963eb2e8f3b29dae1730edd754aeb579beb7ab2e4b5cfd178f087a6d44a1af35dd8af125c08bece5

  • SSDEEP

    6144:YRthERv55G5ke9MRs0On1SIFs7Bqwtj9kJ8c0IITjZ0N7/cYL9duz4hwOUu808OE:EgR5GdCs0O1BkBqwtjFc0fTjZOT59ozt

Malware Config

Targets

    • Target

      13f1e732aafb6b1be1aee5d5fe03ca11_JaffaCakes118

    • Size

      384KB

    • MD5

      13f1e732aafb6b1be1aee5d5fe03ca11

    • SHA1

      284aeaffac85eb583d53b3cff2b950361c5aa1a4

    • SHA256

      939a18217e9f353396fe233dfd742a872b6c1ec265313795d74e238d294cc7ad

    • SHA512

      866c3c30bdee0380394d1b8eaa2673f9c226552427eed2b8963eb2e8f3b29dae1730edd754aeb579beb7ab2e4b5cfd178f087a6d44a1af35dd8af125c08bece5

    • SSDEEP

      6144:YRthERv55G5ke9MRs0On1SIFs7Bqwtj9kJ8c0IITjZ0N7/cYL9duz4hwOUu808OE:EgR5GdCs0O1BkBqwtjFc0fTjZOT59ozt

    • Windows security bypass

    • Disables taskbar notifications via registry modification

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Windows security modification

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Impair Defenses

2
T1562

Disable or Modify Tools

2
T1562.001

Modify Registry

3
T1112

Tasks