General

  • Target

    1a84bd5584f5462759edbc0343b76354_JaffaCakes118

  • Size

    1.9MB

  • Sample

    240701-jt44fatdnp

  • MD5

    1a84bd5584f5462759edbc0343b76354

  • SHA1

    8be7416d240281ee3aef80b5fcb8a3361b271600

  • SHA256

    ae5136e13dd396ed5743f25a6d2a1ba1b736b0ea68ea05dd02f0ddab6ebd95b8

  • SHA512

    caeb6ca0334dfa0032183f590a1ee15d666a4f6dcaf0f81a87cc5ea92516e4eb56005cc423aae6afb4d7c1562ed58e7fe4b1cda11d122d7ed2c7408ecb663bb3

  • SSDEEP

    49152:oOYHH92v0nnW/8mNfqj7KNybKNuJ3Ek9EYC:HHNyAKEf

Malware Config

Targets

    • Target

      1a84bd5584f5462759edbc0343b76354_JaffaCakes118

    • Size

      1.9MB

    • MD5

      1a84bd5584f5462759edbc0343b76354

    • SHA1

      8be7416d240281ee3aef80b5fcb8a3361b271600

    • SHA256

      ae5136e13dd396ed5743f25a6d2a1ba1b736b0ea68ea05dd02f0ddab6ebd95b8

    • SHA512

      caeb6ca0334dfa0032183f590a1ee15d666a4f6dcaf0f81a87cc5ea92516e4eb56005cc423aae6afb4d7c1562ed58e7fe4b1cda11d122d7ed2c7408ecb663bb3

    • SSDEEP

      49152:oOYHH92v0nnW/8mNfqj7KNybKNuJ3Ek9EYC:HHNyAKEf

    • Darkcomet

      DarkComet is a remote access trojan (RAT) developed by Jean-Pierre Lesueur.

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

4
T1012

System Information Discovery

4
T1082

Virtualization/Sandbox Evasion

1
T1497

Tasks