General

  • Target

    1baf244a0b0646b0f335c5152504b7e7_JaffaCakes118

  • Size

    485KB

  • Sample

    240701-r1kmdaxamh

  • MD5

    1baf244a0b0646b0f335c5152504b7e7

  • SHA1

    08fb91a5961abb7eaf43dba91b00231276fc4873

  • SHA256

    b503e554acc12f11c3a6add2f41f96e86ff3ba03e6f2ceeb76785b4b5200212c

  • SHA512

    4aa6966f9750ad52712692ce06373f9cb24be9abdf453e756b66c3f19172b024d9588a3e69935d70330edb89c91ea58a1116a827b499123da2c454fe71f1cf6e

  • SSDEEP

    6144:gMA+Unkc+JnFwsDyqs+avTOnNQsbzNDP7uT3Tm2XrHuOqBaD8usU8j5dV0G4tGWl:TFnWGnavTaNfbzNn8BcPV7OGDWkKrX

Score
7/10

Malware Config

Targets

    • Target

      1baf244a0b0646b0f335c5152504b7e7_JaffaCakes118

    • Size

      485KB

    • MD5

      1baf244a0b0646b0f335c5152504b7e7

    • SHA1

      08fb91a5961abb7eaf43dba91b00231276fc4873

    • SHA256

      b503e554acc12f11c3a6add2f41f96e86ff3ba03e6f2ceeb76785b4b5200212c

    • SHA512

      4aa6966f9750ad52712692ce06373f9cb24be9abdf453e756b66c3f19172b024d9588a3e69935d70330edb89c91ea58a1116a827b499123da2c454fe71f1cf6e

    • SSDEEP

      6144:gMA+Unkc+JnFwsDyqs+avTOnNQsbzNDP7uT3Tm2XrHuOqBaD8usU8j5dV0G4tGWl:TFnWGnavTaNfbzNn8BcPV7OGDWkKrX

    Score
    7/10
    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

System Information Discovery

1
T1082

Virtualization/Sandbox Evasion

1
T1497

Tasks