General

  • Target

    1c83a491dc84689ba35c6d881578b61f_JaffaCakes118

  • Size

    4.0MB

  • Sample

    240701-z1185atepk

  • MD5

    1c83a491dc84689ba35c6d881578b61f

  • SHA1

    89e2665f9249003ead17ec92072d820edb54efe1

  • SHA256

    696821fe58956fe84442e2e536a4551cca48d8477b536bc7714a2ad2a78af7e7

  • SHA512

    e12ddcfca8cd2fd3fe0ab8a90c38bf8fd19be4f8231c3191b44b28fd10a1781feebc93ed7e0305552588706b63fc5f22381a62b7bec154e87b9f869a347a69b7

  • SSDEEP

    98304:NbtJfSKbza2K3YUu7hoBBjiKiy/ZCvwaFo9OSg11fE:NbjbpK3LT2KDIoaF6OSgPs

Malware Config

Targets

    • Target

      1c83a491dc84689ba35c6d881578b61f_JaffaCakes118

    • Size

      4.0MB

    • MD5

      1c83a491dc84689ba35c6d881578b61f

    • SHA1

      89e2665f9249003ead17ec92072d820edb54efe1

    • SHA256

      696821fe58956fe84442e2e536a4551cca48d8477b536bc7714a2ad2a78af7e7

    • SHA512

      e12ddcfca8cd2fd3fe0ab8a90c38bf8fd19be4f8231c3191b44b28fd10a1781feebc93ed7e0305552588706b63fc5f22381a62b7bec154e87b9f869a347a69b7

    • SSDEEP

      98304:NbtJfSKbza2K3YUu7hoBBjiKiy/ZCvwaFo9OSg11fE:NbjbpK3LT2KDIoaF6OSgPs

    • Stops running service(s)

    • Uses Session Manager for persistence

      Creates Session Manager registry key to run executable early in system boot.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Execution

System Services

1
T1569

Service Execution

1
T1569.002

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Boot or Logon Autostart Execution

2
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Defense Evasion

Impair Defenses

1
T1562

Modify Registry

2
T1112

Impact

Service Stop

1
T1489

Tasks