General

  • Target

    1a9b56bfb288c007b6d4d85fadb8b183_JaffaCakes118

  • Size

    1.3MB

  • Sample

    240701-kd8mcsvdnr

  • MD5

    1a9b56bfb288c007b6d4d85fadb8b183

  • SHA1

    494b8ee67bf0ef2b39696efd00195ac4fbf35430

  • SHA256

    1b0bc72089d28ab55c4f4c51bc92173b3a2be21f7bcaa4157447ac4930be7c4a

  • SHA512

    75a660e19a56b72fb030a7ce7c3d56d87a077ffdd1521232684b02262d9ac42b2dbc7f5f97dc857b8c4d59cdf5bb76e0b81acd8616e0e30fa24613d9770f68a7

  • SSDEEP

    24576:CN4G96RfkkFkRKJkQ8+FSkDa3RnqXsIkEBpj7/w/TPx693/6Lq32CbQRsqrT:CN396JFk1Q8VkmBSsIzBl72Lw9v6LiFe

Score
7/10

Malware Config

Targets

    • Target

      1a9b56bfb288c007b6d4d85fadb8b183_JaffaCakes118

    • Size

      1.3MB

    • MD5

      1a9b56bfb288c007b6d4d85fadb8b183

    • SHA1

      494b8ee67bf0ef2b39696efd00195ac4fbf35430

    • SHA256

      1b0bc72089d28ab55c4f4c51bc92173b3a2be21f7bcaa4157447ac4930be7c4a

    • SHA512

      75a660e19a56b72fb030a7ce7c3d56d87a077ffdd1521232684b02262d9ac42b2dbc7f5f97dc857b8c4d59cdf5bb76e0b81acd8616e0e30fa24613d9770f68a7

    • SSDEEP

      24576:CN4G96RfkkFkRKJkQ8+FSkDa3RnqXsIkEBpj7/w/TPx693/6Lq32CbQRsqrT:CN396JFk1Q8VkmBSsIzBl72Lw9v6LiFe

    Score
    7/10
    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Tasks