General

  • Target

    1ac2103e546fc733b1279f2019392366_JaffaCakes118

  • Size

    1.4MB

  • Sample

    240701-ldvk6stdmc

  • MD5

    1ac2103e546fc733b1279f2019392366

  • SHA1

    973e92648372364316f860026ac759505c4ec640

  • SHA256

    a526ceff827548b40775bfd3ba8712f6a0ec9c6b17b0a115d570c430382a1511

  • SHA512

    b47ff669f3592dce5501596ad4ea37a57aab5c118d635ea462684d29faa0995124dbf4ade51952da223cec8a3a957a5d7f3a2fba9004cbb06613a30530c3db0e

  • SSDEEP

    24576:jJNW5bRg3Zur9Q9+y0x2rw9W0ZjXuCkhW0k07lx73rf4G5c+M0UTgb:tc5NCDS0wf9X3Ol7lx77Z5c

Score
7/10

Malware Config

Targets

    • Target

      1ac2103e546fc733b1279f2019392366_JaffaCakes118

    • Size

      1.4MB

    • MD5

      1ac2103e546fc733b1279f2019392366

    • SHA1

      973e92648372364316f860026ac759505c4ec640

    • SHA256

      a526ceff827548b40775bfd3ba8712f6a0ec9c6b17b0a115d570c430382a1511

    • SHA512

      b47ff669f3592dce5501596ad4ea37a57aab5c118d635ea462684d29faa0995124dbf4ade51952da223cec8a3a957a5d7f3a2fba9004cbb06613a30530c3db0e

    • SSDEEP

      24576:jJNW5bRg3Zur9Q9+y0x2rw9W0ZjXuCkhW0k07lx73rf4G5c+M0UTgb:tc5NCDS0wf9X3Ol7lx77Z5c

    Score
    7/10
    • Executes dropped EXE

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Loads dropped DLL

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Tasks