Analysis

  • max time kernel
    119s
  • max time network
    124s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 18:13

General

  • Target

    1c0225bdf8e7c7fc956ab3d212e75c10_JaffaCakes118.dll

  • Size

    524KB

  • MD5

    1c0225bdf8e7c7fc956ab3d212e75c10

  • SHA1

    bec5cf0c2ab8802229ef5c27a28f021db3241ff8

  • SHA256

    6fe20ff062b6984db3b53409681f9effd51ba1f8d52583ba932148ebdf753435

  • SHA512

    3b31ede8b4296c7b660fcd9f9aee9480e211bd9e438165888cee3e7e45a286281e46fcfac975a6f5c7051b3b536b8b318331400219a98bb23361366f38d86f95

  • SSDEEP

    12288:P3dia0V/LcQzxKfptPZ8aS833molJV4N5SMsD2Ksy/LWC21W:x0V/LvzwRoSmolJV46MesKLf21W

Score
8/10

Malware Config

Signatures

  • Blocklisted process makes network request 2 IoCs
  • VMProtect packed file 4 IoCs

    Detects executables packed with VMProtect commercial packer.

  • Drops file in System32 directory 1 IoCs
  • Suspicious use of AdjustPrivilegeToken 40 IoCs
  • Suspicious use of WriteProcessMemory 11 IoCs

Processes

  • C:\Windows\system32\rundll32.exe
    rundll32.exe C:\Users\Admin\AppData\Local\Temp\1c0225bdf8e7c7fc956ab3d212e75c10_JaffaCakes118.dll,#1
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:2248
    • C:\Windows\SysWOW64\rundll32.exe
      rundll32.exe C:\Users\Admin\AppData\Local\Temp\1c0225bdf8e7c7fc956ab3d212e75c10_JaffaCakes118.dll,#1
      2⤵
      • Blocklisted process makes network request
      • Drops file in System32 directory
      • Suspicious use of WriteProcessMemory
      PID:860
      • C:\Windows\SysWOW64\Wbem\wmic.exe
        wmic process 860 call terminate
        3⤵
        • Suspicious use of AdjustPrivilegeToken
        PID:2520

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/860-2-0x0000000010000000-0x0000000010084000-memory.dmp
    Filesize

    528KB

  • memory/860-1-0x0000000010000000-0x0000000010084000-memory.dmp
    Filesize

    528KB

  • memory/860-0-0x0000000010000000-0x0000000010084000-memory.dmp
    Filesize

    528KB

  • memory/860-3-0x0000000010000000-0x0000000010084000-memory.dmp
    Filesize

    528KB