General

  • Target

    1a89edbfd13fa4cd04695425476bc795_JaffaCakes118

  • Size

    96KB

  • Sample

    240701-jzsmlazhpg

  • MD5

    1a89edbfd13fa4cd04695425476bc795

  • SHA1

    5fe16411add37ae8bf46551882ddf59fc0f11c7e

  • SHA256

    673226adeedd79b6e7c2fb1e9d5b28271ff5a467d5740831bd55971c7b23a92e

  • SHA512

    426c7caeac9fce6563b926586d90e8163cd6c572694c9a82568b0b07174d4b981b49a71eeb1c92d57ca79a17cdd2520f185f8554c2bc2fde616a5ecaf2d5640c

  • SSDEEP

    1536:cWULzauTQQFO5Bvfk+6Mz9dat+Ug3+z6OyoraWEsWFVPIY3m1FToBw/ChT3PUSQ:VCausWOTfk0at+Um+z6OyoDErCYCRoBx

Malware Config

Targets

    • Target

      1a89edbfd13fa4cd04695425476bc795_JaffaCakes118

    • Size

      96KB

    • MD5

      1a89edbfd13fa4cd04695425476bc795

    • SHA1

      5fe16411add37ae8bf46551882ddf59fc0f11c7e

    • SHA256

      673226adeedd79b6e7c2fb1e9d5b28271ff5a467d5740831bd55971c7b23a92e

    • SHA512

      426c7caeac9fce6563b926586d90e8163cd6c572694c9a82568b0b07174d4b981b49a71eeb1c92d57ca79a17cdd2520f185f8554c2bc2fde616a5ecaf2d5640c

    • SSDEEP

      1536:cWULzauTQQFO5Bvfk+6Mz9dat+Ug3+z6OyoraWEsWFVPIY3m1FToBw/ChT3PUSQ:VCausWOTfk0at+Um+z6OyoDErCYCRoBx

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Discovery

Query Registry

1
T1012

Tasks