General

  • Target

    1c5eb0e8f00fd584e8d1d3006278fe76_JaffaCakes118

  • Size

    165KB

  • Sample

    240701-y5dg7a1flk

  • MD5

    1c5eb0e8f00fd584e8d1d3006278fe76

  • SHA1

    03f5aa75940b9176a97ac41257f306c33cca93da

  • SHA256

    e026f6f1a5a4f5b39e68c8cdb050334174764d2c7fe041073c6e64872a3a4099

  • SHA512

    592c5856367f942c29f9f88c7ed20f65eb453475991ffafa11cd72b4c45ca3e58f47af0d4daf6cda2a3800de45789d55596bfcfe3588ee4f7f77417e52474590

  • SSDEEP

    3072:yo5Htro+64OBGLvtwT+rGkLB0oA50BFLqlNyoNCzN2D3zCCR9GPU1:351llOBGLvuT+rjLBxAblNyN2zz7RWM

Malware Config

Targets

    • Target

      1c5eb0e8f00fd584e8d1d3006278fe76_JaffaCakes118

    • Size

      165KB

    • MD5

      1c5eb0e8f00fd584e8d1d3006278fe76

    • SHA1

      03f5aa75940b9176a97ac41257f306c33cca93da

    • SHA256

      e026f6f1a5a4f5b39e68c8cdb050334174764d2c7fe041073c6e64872a3a4099

    • SHA512

      592c5856367f942c29f9f88c7ed20f65eb453475991ffafa11cd72b4c45ca3e58f47af0d4daf6cda2a3800de45789d55596bfcfe3588ee4f7f77417e52474590

    • SSDEEP

      3072:yo5Htro+64OBGLvtwT+rGkLB0oA50BFLqlNyoNCzN2D3zCCR9GPU1:351llOBGLvuT+rjLBxAblNyN2zz7RWM

    • Modifies firewall policy service

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

2
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Tasks