General

  • Target

    1ac25de2543e8b8af762944678d52314_JaffaCakes118

  • Size

    152KB

  • Sample

    240701-ldzvwstdmg

  • MD5

    1ac25de2543e8b8af762944678d52314

  • SHA1

    27a4e953dddea51d8fee25c55871848daa2ee72a

  • SHA256

    cd098626db09e5d348b06a8423c71a7270270aa2c1b6de6346b890aa5de9a74f

  • SHA512

    4becd7c656d6c2ff546e5182317f72a2325a872e5a9af8411c877808c35b1a5841192192589bfe54fe637149bf81512211813fe70a5a341715d78be9c9a2036c

  • SSDEEP

    1536:1msNjoc0DNq89se8pbRYbRH6xjazyrOOq80ktMUhAwrz4i0+X9FYoa:cOjocENzRWGzyrO381tMUSwrjX9ra

Score
7/10

Malware Config

Targets

    • Target

      1ac25de2543e8b8af762944678d52314_JaffaCakes118

    • Size

      152KB

    • MD5

      1ac25de2543e8b8af762944678d52314

    • SHA1

      27a4e953dddea51d8fee25c55871848daa2ee72a

    • SHA256

      cd098626db09e5d348b06a8423c71a7270270aa2c1b6de6346b890aa5de9a74f

    • SHA512

      4becd7c656d6c2ff546e5182317f72a2325a872e5a9af8411c877808c35b1a5841192192589bfe54fe637149bf81512211813fe70a5a341715d78be9c9a2036c

    • SSDEEP

      1536:1msNjoc0DNq89se8pbRYbRH6xjazyrOOq80ktMUhAwrz4i0+X9FYoa:cOjocENzRWGzyrO381tMUSwrjX9ra

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Loads dropped DLL

    • Installs/modifies Browser Helper Object

      BHOs are DLL modules which act as plugins for Internet Explorer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Browser Extensions

1
T1176

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Tasks