General

  • Target

    1be78540dc5a5d2a6d82abbd8139f57e_JaffaCakes118

  • Size

    157KB

  • Sample

    240701-v7bvlavbjq

  • MD5

    1be78540dc5a5d2a6d82abbd8139f57e

  • SHA1

    85fe7c0656e61aaad685c77b44c58cc21a594006

  • SHA256

    28275e93219610855522bcfe34afb25f571c5eeedfa805ca2689d3ce7bba9086

  • SHA512

    a941f982eec5e1860333fe7f391035265513af457f239173682194a8ce556bbcd061062fc08ed74871386012306f2199c69fd2b1810fcc7ec171954aec93d3d7

  • SSDEEP

    3072:wxbjR9outXvCOS8DD8RAenjlGvLKFhK+hHnO+nQOtsL25QdZr94:wxfnoSnDqn5ALmM+hHtQjSEZ54

Malware Config

Targets

    • Target

      1be78540dc5a5d2a6d82abbd8139f57e_JaffaCakes118

    • Size

      157KB

    • MD5

      1be78540dc5a5d2a6d82abbd8139f57e

    • SHA1

      85fe7c0656e61aaad685c77b44c58cc21a594006

    • SHA256

      28275e93219610855522bcfe34afb25f571c5eeedfa805ca2689d3ce7bba9086

    • SHA512

      a941f982eec5e1860333fe7f391035265513af457f239173682194a8ce556bbcd061062fc08ed74871386012306f2199c69fd2b1810fcc7ec171954aec93d3d7

    • SSDEEP

      3072:wxbjR9outXvCOS8DD8RAenjlGvLKFhK+hHnO+nQOtsL25QdZr94:wxfnoSnDqn5ALmM+hHtQjSEZ54

    • Modifies firewall policy service

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Drops file in Drivers directory

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

1
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Tasks