General

  • Target

    1aaacfa5ba89e732192ef05c1af91ef7_JaffaCakes118

  • Size

    79KB

  • Sample

    240701-kr8jhswarj

  • MD5

    1aaacfa5ba89e732192ef05c1af91ef7

  • SHA1

    8c67aee19640bdf8394c31bcbfe90a6d3981516b

  • SHA256

    aceb10dd1cb6c455e0f31b80446ea9232af493c5a5e4cc6ae0befb1d4f861cac

  • SHA512

    4272a175ee0a1afd828ccc423482100b37f35e652524dfecd7f9ffc38e3d8e4f0816d29b081983c79eaadb64ceddd4a9e632941c96520ba74899a36b7e7b0132

  • SSDEEP

    1536:Geff508RTuuhTDAA8//YEfsWfcBNhsBNSLzv8YpObL9YkIVerGAew4P/51x/JtSG:3ff508RTuuhTDAAY/YEfhfopLzvd7ZDd

Malware Config

Targets

    • Target

      1aaacfa5ba89e732192ef05c1af91ef7_JaffaCakes118

    • Size

      79KB

    • MD5

      1aaacfa5ba89e732192ef05c1af91ef7

    • SHA1

      8c67aee19640bdf8394c31bcbfe90a6d3981516b

    • SHA256

      aceb10dd1cb6c455e0f31b80446ea9232af493c5a5e4cc6ae0befb1d4f861cac

    • SHA512

      4272a175ee0a1afd828ccc423482100b37f35e652524dfecd7f9ffc38e3d8e4f0816d29b081983c79eaadb64ceddd4a9e632941c96520ba74899a36b7e7b0132

    • SSDEEP

      1536:Geff508RTuuhTDAA8//YEfsWfcBNhsBNSLzv8YpObL9YkIVerGAew4P/51x/JtSG:3ff508RTuuhTDAAY/YEfhfopLzvd7ZDd

    • Loads dropped DLL

    • Adds Run key to start application

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

    • Modifies WinLogon

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Browser Extensions

1
T1176

Privilege Escalation

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

3
T1112

Tasks