General

  • Target

    1e34eb547e4f0adc4484e641af67e3a6_JaffaCakes118

  • Size

    55KB

  • Sample

    240702-ghenasserk

  • MD5

    1e34eb547e4f0adc4484e641af67e3a6

  • SHA1

    59e9febb72bf809b7c09d02cd234617d1d2f65d2

  • SHA256

    d2de00d5b02fd0ac20eb4ea1aed9509fc98c62194bbc6a426c955ea929be9214

  • SHA512

    58d43cc38a20811ba99c7c1b7ef51a2f6d642b57b711cd4e08b79301ad63ed8dfc39876db31727bf5fc002c741ff8cf41d717a8d22002233169cc88f99b3f9de

  • SSDEEP

    1536:sMbImeWlLK3Q/tHmTCXhjx+IQurQnaZmDn8G5ybes:JreWlLK3iHRx+IzrUaUj6b

Malware Config

Targets

    • Target

      1e34eb547e4f0adc4484e641af67e3a6_JaffaCakes118

    • Size

      55KB

    • MD5

      1e34eb547e4f0adc4484e641af67e3a6

    • SHA1

      59e9febb72bf809b7c09d02cd234617d1d2f65d2

    • SHA256

      d2de00d5b02fd0ac20eb4ea1aed9509fc98c62194bbc6a426c955ea929be9214

    • SHA512

      58d43cc38a20811ba99c7c1b7ef51a2f6d642b57b711cd4e08b79301ad63ed8dfc39876db31727bf5fc002c741ff8cf41d717a8d22002233169cc88f99b3f9de

    • SSDEEP

      1536:sMbImeWlLK3Q/tHmTCXhjx+IQurQnaZmDn8G5ybes:JreWlLK3iHRx+IzrUaUj6b

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks