General

  • Target

    1a803048ae782e99e2cf5b7c58c0ebb4_JaffaCakes118

  • Size

    108KB

  • Sample

    240701-jp87lazekb

  • MD5

    1a803048ae782e99e2cf5b7c58c0ebb4

  • SHA1

    f2bf3abd85288b26eec1df82ccf35bbaf894f1c9

  • SHA256

    56d76e9194322de41ff0b04b66d8b1dad5cdb9c0d786b9ca4fcc0d51efdfa557

  • SHA512

    b90afd2217c3dc71ebe2b2997066027bc8ec74855c476100b07f9d48756bca1529350be0502512b0e19aaddea88cc7d16ffc56aeb64a5317b016b83cfed82241

  • SSDEEP

    1536:NQ7+EmDciDoKIOLiSRtcpFXebkT1zG2DMv5jQhKJ3psYfHwRVcdTX3kuJd:K7inD1IYnWuO1Chh0MFpsFRi9X3kuJd

Malware Config

Targets

    • Target

      1a803048ae782e99e2cf5b7c58c0ebb4_JaffaCakes118

    • Size

      108KB

    • MD5

      1a803048ae782e99e2cf5b7c58c0ebb4

    • SHA1

      f2bf3abd85288b26eec1df82ccf35bbaf894f1c9

    • SHA256

      56d76e9194322de41ff0b04b66d8b1dad5cdb9c0d786b9ca4fcc0d51efdfa557

    • SHA512

      b90afd2217c3dc71ebe2b2997066027bc8ec74855c476100b07f9d48756bca1529350be0502512b0e19aaddea88cc7d16ffc56aeb64a5317b016b83cfed82241

    • SSDEEP

      1536:NQ7+EmDciDoKIOLiSRtcpFXebkT1zG2DMv5jQhKJ3psYfHwRVcdTX3kuJd:K7inD1IYnWuO1Chh0MFpsFRi9X3kuJd

    • Windows security bypass

    • Deletes itself

    • Windows security modification

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Impair Defenses

2
T1562

Disable or Modify Tools

2
T1562.001

Modify Registry

4
T1112

Discovery

System Information Discovery

1
T1082

Tasks