General

  • Target

    1d6958990c8c4f5b9b93efa692b84937_JaffaCakes118

  • Size

    5.0MB

  • Sample

    240702-zq79patalm

  • MD5

    1d6958990c8c4f5b9b93efa692b84937

  • SHA1

    58bc6052ee6a13dc4711ca73df029a694f6e7239

  • SHA256

    716954bdf4ef6882a71c8f2aa3981190da7777b50a3988069bb68eed17c7ddc8

  • SHA512

    cb1445e197763d3ae28e8b7186a5f57cd8f34cbcba7c627d7004eb6dddbca67526ae721aff62d26c21b3585c0caef698b236194c90619c970099a5eced8d2682

  • SSDEEP

    24576:SbLgddQhfdmMSirYbcMNgef0B+RdhAdmv1LJMfcH9EP:SnAQqMSPbcBVIRdhnvxJM0H9

Malware Config

Targets

    • Target

      1d6958990c8c4f5b9b93efa692b84937_JaffaCakes118

    • Size

      5.0MB

    • MD5

      1d6958990c8c4f5b9b93efa692b84937

    • SHA1

      58bc6052ee6a13dc4711ca73df029a694f6e7239

    • SHA256

      716954bdf4ef6882a71c8f2aa3981190da7777b50a3988069bb68eed17c7ddc8

    • SHA512

      cb1445e197763d3ae28e8b7186a5f57cd8f34cbcba7c627d7004eb6dddbca67526ae721aff62d26c21b3585c0caef698b236194c90619c970099a5eced8d2682

    • SSDEEP

      24576:SbLgddQhfdmMSirYbcMNgef0B+RdhAdmv1LJMfcH9EP:SnAQqMSPbcBVIRdhnvxJM0H9

    • Wannacry

      WannaCry is a ransomware cryptoworm.

    • Contacts a large (3330) amount of remote hosts

      This may indicate a network scan to discover remotely running services.

    • Executes dropped EXE

    • Creates a large amount of network flows

      This may indicate a network scan to discover remotely running services.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Tasks