General

  • Target

    1a98bfabfe77a6075f78d20867c12e00_JaffaCakes118

  • Size

    88KB

  • Sample

    240701-kb61ra1fjb

  • MD5

    1a98bfabfe77a6075f78d20867c12e00

  • SHA1

    10ad95d12a670b34538bbc49e010ca457b5e5dbf

  • SHA256

    d4bbf9776c8c9bb22feb25501e3bf31f2110f655ae81af3320c77dde0e3140ba

  • SHA512

    c7ca954c296a6eaa193866f6dc740210693aa79e8691c7bfb14b24372bfe769aa96760378683a2e37fa20f0f9637c65b2e5c83f8c6e9784d5a43d510fa03e1d6

  • SSDEEP

    1536:dXNXdlRH+Dwk4cSGesvhC8plnQ85+HwClgfTQqPTFTCtOQ8Ccfit:ddtlRH+UxGzh3HQ85+QqoTBfit

Malware Config

Targets

    • Target

      1a98bfabfe77a6075f78d20867c12e00_JaffaCakes118

    • Size

      88KB

    • MD5

      1a98bfabfe77a6075f78d20867c12e00

    • SHA1

      10ad95d12a670b34538bbc49e010ca457b5e5dbf

    • SHA256

      d4bbf9776c8c9bb22feb25501e3bf31f2110f655ae81af3320c77dde0e3140ba

    • SHA512

      c7ca954c296a6eaa193866f6dc740210693aa79e8691c7bfb14b24372bfe769aa96760378683a2e37fa20f0f9637c65b2e5c83f8c6e9784d5a43d510fa03e1d6

    • SSDEEP

      1536:dXNXdlRH+Dwk4cSGesvhC8plnQ85+HwClgfTQqPTFTCtOQ8Ccfit:ddtlRH+UxGzh3HQ85+QqoTBfit

    • Executes dropped EXE

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Modify Registry

1
T1112

Tasks