General

  • Target

    1b0345e97b24720ac1f907b04f84f1ef_JaffaCakes118

  • Size

    143KB

  • Sample

    240701-myjvvaxdkb

  • MD5

    1b0345e97b24720ac1f907b04f84f1ef

  • SHA1

    cde1d9dceb37cf0adebdf8d318a24b3ac1406af8

  • SHA256

    cbad509a0e6fae8870308ae58dbc10507c5a76159315e8cfe1923086924491d6

  • SHA512

    3f7d1c0a83b865b743a1ff01718ac99b254cda3fea7366ea304b5f7c39c6490d3f928afe88da772f0fe8092c6d7b1681c76ba24b39dde0418504c57470fc4bf3

  • SSDEEP

    3072:JaiKXvKJW5zpd7rVXJ1RRA/SlXJKY/X1AKmo7D9NJO0vS:B6vKJqzNw/+vF2eDnvS

Malware Config

Targets

    • Target

      1b0345e97b24720ac1f907b04f84f1ef_JaffaCakes118

    • Size

      143KB

    • MD5

      1b0345e97b24720ac1f907b04f84f1ef

    • SHA1

      cde1d9dceb37cf0adebdf8d318a24b3ac1406af8

    • SHA256

      cbad509a0e6fae8870308ae58dbc10507c5a76159315e8cfe1923086924491d6

    • SHA512

      3f7d1c0a83b865b743a1ff01718ac99b254cda3fea7366ea304b5f7c39c6490d3f928afe88da772f0fe8092c6d7b1681c76ba24b39dde0418504c57470fc4bf3

    • SSDEEP

      3072:JaiKXvKJW5zpd7rVXJ1RRA/SlXJKY/X1AKmo7D9NJO0vS:B6vKJqzNw/+vF2eDnvS

    • Event Triggered Execution: AppInit DLLs

      Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.

    • Deletes itself

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

AppInit DLLs

1
T1546.010

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Event Triggered Execution

1
T1546

AppInit DLLs

1
T1546.010

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks