General
-
Target
1c2dc280425180936a40bc28c1453754_JaffaCakes118
-
Size
167KB
-
Sample
240701-xxc11svbkb
-
MD5
1c2dc280425180936a40bc28c1453754
-
SHA1
845074e871bcea11973c5670ec008460d49aaa76
-
SHA256
97c42a867a707b17a33ff2cfb2b2407df60c592139763855594f1ed33cee25f4
-
SHA512
41dff89d8d24cef5113aebb1d1561de8ec0ba60eddd21674a5e85ec5557360b3ab547ad7eeff6b7c44dae2f1b24554df495fcb9c896f3177247f223fe7b9cc1e
-
SSDEEP
3072:/NQKPWDyBI0fFJltZrpReFX3sOb+yD91jcpdhyzfNQbFPUcwNusHdM66:/NSDyBIkFthpU+Ks7YmFPUgP
Static task
static1
Behavioral task
behavioral1
Sample
1c2dc280425180936a40bc28c1453754_JaffaCakes118.exe
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
1c2dc280425180936a40bc28c1453754_JaffaCakes118.exe
Resource
win10v2004-20240508-en
Malware Config
Extracted
sality
http://89.119.67.154/testo5/
http://kukutrustnet777.info/home.gif
http://kukutrustnet888.info/home.gif
http://kukutrustnet987.info/home.gif
Targets
-
-
Target
1c2dc280425180936a40bc28c1453754_JaffaCakes118
-
Size
167KB
-
MD5
1c2dc280425180936a40bc28c1453754
-
SHA1
845074e871bcea11973c5670ec008460d49aaa76
-
SHA256
97c42a867a707b17a33ff2cfb2b2407df60c592139763855594f1ed33cee25f4
-
SHA512
41dff89d8d24cef5113aebb1d1561de8ec0ba60eddd21674a5e85ec5557360b3ab547ad7eeff6b7c44dae2f1b24554df495fcb9c896f3177247f223fe7b9cc1e
-
SSDEEP
3072:/NQKPWDyBI0fFJltZrpReFX3sOb+yD91jcpdhyzfNQbFPUcwNusHdM66:/NSDyBIkFthpU+Ks7YmFPUgP
-
Disables RegEdit via registry modification
-
Disables Task Manager via registry modification
-
Modifies Windows Firewall
-
MITRE ATT&CK Matrix ATT&CK v13
Persistence
Create or Modify System Process
1Windows Service
1Event Triggered Execution
1Netsh Helper DLL
1Privilege Escalation
Abuse Elevation Control Mechanism
1Bypass User Account Control
1Create or Modify System Process
1Windows Service
1Event Triggered Execution
1Netsh Helper DLL
1