General

  • Target

    1ea729b1bb37081f884742866d10bfc5_JaffaCakes118

  • Size

    148KB

  • Sample

    240702-kgwrzavapb

  • MD5

    1ea729b1bb37081f884742866d10bfc5

  • SHA1

    a58104cce2a151448f0a979525c90de4b47fed99

  • SHA256

    3f4e53acbbb9bc6b566fe434380e75dae585e390d53d806b4155458201002652

  • SHA512

    8f78280f0ef88c404c39a4c14e5ae6cf3ca1587f00ef40664c22b6cd09e0fad602d180bb15733e191e1a3fbb05ffabca2272d415002826269dbd0c12c6707dc6

  • SSDEEP

    3072:n3rmNZVwqnUxIcPRb0ZQwCcRw4eX/OA8ik/QlbI:nWwmUxIYQqxH8iYB

Malware Config

Targets

    • Target

      1ea729b1bb37081f884742866d10bfc5_JaffaCakes118

    • Size

      148KB

    • MD5

      1ea729b1bb37081f884742866d10bfc5

    • SHA1

      a58104cce2a151448f0a979525c90de4b47fed99

    • SHA256

      3f4e53acbbb9bc6b566fe434380e75dae585e390d53d806b4155458201002652

    • SHA512

      8f78280f0ef88c404c39a4c14e5ae6cf3ca1587f00ef40664c22b6cd09e0fad602d180bb15733e191e1a3fbb05ffabca2272d415002826269dbd0c12c6707dc6

    • SSDEEP

      3072:n3rmNZVwqnUxIcPRb0ZQwCcRw4eX/OA8ik/QlbI:nWwmUxIYQqxH8iYB

    • Modifies firewall policy service

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

2
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Discovery

System Information Discovery

1
T1082

Tasks