General

  • Target

    1f76aa90b27df796ea477edc2e78fe46_JaffaCakes118

  • Size

    1.2MB

  • Sample

    240702-qp8pdsthka

  • MD5

    1f76aa90b27df796ea477edc2e78fe46

  • SHA1

    de087d082ef29e20cc28a4d80dd6051d14fcfddc

  • SHA256

    96742015932d8c59672a2e3d58768b637a7a75d08bd3032a008af1bac6ec6001

  • SHA512

    227494a15c6afed9c3784d7c997a8116b8a093aecf0c8dae93c064a4b5f9f061d1c583997e4c5ef52989940327933780c509dde4d8346afe56e6a6f03e310ec7

  • SSDEEP

    12288:IqOPajQUXXP8QvLWFx6Mo5rippDC7ee1hpls4Ey+QDK+3S:InajQEPnvg6PhWDC750QDK+3S

Malware Config

Targets

    • Target

      1f76aa90b27df796ea477edc2e78fe46_JaffaCakes118

    • Size

      1.2MB

    • MD5

      1f76aa90b27df796ea477edc2e78fe46

    • SHA1

      de087d082ef29e20cc28a4d80dd6051d14fcfddc

    • SHA256

      96742015932d8c59672a2e3d58768b637a7a75d08bd3032a008af1bac6ec6001

    • SHA512

      227494a15c6afed9c3784d7c997a8116b8a093aecf0c8dae93c064a4b5f9f061d1c583997e4c5ef52989940327933780c509dde4d8346afe56e6a6f03e310ec7

    • SSDEEP

      12288:IqOPajQUXXP8QvLWFx6Mo5rippDC7ee1hpls4Ey+QDK+3S:InajQEPnvg6PhWDC750QDK+3S

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

System Information Discovery

1
T1082

Tasks