General

  • Target

    1e7df3b86d6182299290dd03c7453c6c_JaffaCakes118

  • Size

    64KB

  • Sample

    240702-jgb7wsseld

  • MD5

    1e7df3b86d6182299290dd03c7453c6c

  • SHA1

    448e91e1056837e356ec84a4fc57a6f2adba1d97

  • SHA256

    36d6b8b15e90fcf7529fe0e5917bf4d3e13fbf4aa11ec63e8037dbca976a2518

  • SHA512

    2a2371009ecb9e84c3d2e7a707e268660bd98d6229147cb9583d2ad2b9ca485e0db8d7f39d2b6744809bbb030c7117ce48e86c89b9b9d02b5c1df74a80742a43

  • SSDEEP

    1536:5STKjsAltWAZteP/nq0FogvIJ3X/vYpzR:5sKIAltvWPVogv0HYp9

Score
8/10

Malware Config

Targets

    • Target

      1e7df3b86d6182299290dd03c7453c6c_JaffaCakes118

    • Size

      64KB

    • MD5

      1e7df3b86d6182299290dd03c7453c6c

    • SHA1

      448e91e1056837e356ec84a4fc57a6f2adba1d97

    • SHA256

      36d6b8b15e90fcf7529fe0e5917bf4d3e13fbf4aa11ec63e8037dbca976a2518

    • SHA512

      2a2371009ecb9e84c3d2e7a707e268660bd98d6229147cb9583d2ad2b9ca485e0db8d7f39d2b6744809bbb030c7117ce48e86c89b9b9d02b5c1df74a80742a43

    • SSDEEP

      1536:5STKjsAltWAZteP/nq0FogvIJ3X/vYpzR:5sKIAltvWPVogv0HYp9

    Score
    8/10
    • Blocklisted process makes network request

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks