General

  • Target

    1c8341c06eb695aa28d21c067902c031_JaffaCakes118

  • Size

    1.9MB

  • Sample

    240701-z1qgmazdlg

  • MD5

    1c8341c06eb695aa28d21c067902c031

  • SHA1

    70709b323a7983df2828f9f7531f682ec3d51e81

  • SHA256

    f60c7099a22a40dddd8f154c9ccf3a6fff2f78d786afb98f12d8e002315df366

  • SHA512

    3b9d37765425ee36583c587e20a42005fbd81ff6f90d6681655ee54c59f95bcdab35d0949d9ecc1b1fc26e6891450caff35ef41bab997d112db383d70f7ff72d

  • SSDEEP

    24576:9eu9FkFR7dIYzDyBSikMgUiVwhV1Xwz3R/UPQVSEGE050SQ+Xavfw63ENaBXKIaF:UuFkb7VrMfNhwzBcYVE9YfBLBXkjes

Malware Config

Targets

    • Target

      1c8341c06eb695aa28d21c067902c031_JaffaCakes118

    • Size

      1.9MB

    • MD5

      1c8341c06eb695aa28d21c067902c031

    • SHA1

      70709b323a7983df2828f9f7531f682ec3d51e81

    • SHA256

      f60c7099a22a40dddd8f154c9ccf3a6fff2f78d786afb98f12d8e002315df366

    • SHA512

      3b9d37765425ee36583c587e20a42005fbd81ff6f90d6681655ee54c59f95bcdab35d0949d9ecc1b1fc26e6891450caff35ef41bab997d112db383d70f7ff72d

    • SSDEEP

      24576:9eu9FkFR7dIYzDyBSikMgUiVwhV1Xwz3R/UPQVSEGE050SQ+Xavfw63ENaBXKIaF:UuFkb7VrMfNhwzBcYVE9YfBLBXkjes

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

Tasks