General

  • Target

    1ed9b587c0d2b28f78c46732c49b59e1_JaffaCakes118

  • Size

    153KB

  • Sample

    240702-lrmsgszhqq

  • MD5

    1ed9b587c0d2b28f78c46732c49b59e1

  • SHA1

    916d8971873100d5544dd91fe0ccd8d36af046bc

  • SHA256

    18605614e2d91164f3b5892cdbfebc099a8ceeb00b9912654648ac834a86c8ea

  • SHA512

    4c1806e4fa062b2961ccf13422f228d4b2aa25a0131f33d940dbc319b34590603442c264bc1c7261c8bb98a255279f2e803c42b01b648426383a3882a0c3eada

  • SSDEEP

    3072:/qlqSr+upksBHUVf1k47TFPakIUd4dlK4ijn8FQNhyLndezj:/Yq2zpk0SL7Twz84Z4NBz

Score
7/10

Malware Config

Targets

    • Target

      1ed9b587c0d2b28f78c46732c49b59e1_JaffaCakes118

    • Size

      153KB

    • MD5

      1ed9b587c0d2b28f78c46732c49b59e1

    • SHA1

      916d8971873100d5544dd91fe0ccd8d36af046bc

    • SHA256

      18605614e2d91164f3b5892cdbfebc099a8ceeb00b9912654648ac834a86c8ea

    • SHA512

      4c1806e4fa062b2961ccf13422f228d4b2aa25a0131f33d940dbc319b34590603442c264bc1c7261c8bb98a255279f2e803c42b01b648426383a3882a0c3eada

    • SSDEEP

      3072:/qlqSr+upksBHUVf1k47TFPakIUd4dlK4ijn8FQNhyLndezj:/Yq2zpk0SL7Twz84Z4NBz

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks