General

  • Target

    26adc37442f43dd3e1c06c26c3793a56_JaffaCakes118

  • Size

    4.0MB

  • Sample

    240704-3rqb2sydpe

  • MD5

    26adc37442f43dd3e1c06c26c3793a56

  • SHA1

    15d6486f8c6c5c767651d3016624025d2fb34da4

  • SHA256

    f8ae2e6e1e607e7734fd02871d0754d7236e6f6ed9bb501ad6ff5115e40c42c2

  • SHA512

    55d21803162d126d460f95dccb580b85725a209a367a9ba00d00a5057370985bbd9a77689d7d45efb4ce7cec3b74edcaecd33f4d9bba4c9f4e21c371a8cb3765

  • SSDEEP

    98304:MRhxs1zO9FSSVNSt0RzOtk0kCkBptwhBKB0F+w7:GxEO9gSLSt0Ryi0pkBp6rK21

Malware Config

Targets

    • Target

      26adc37442f43dd3e1c06c26c3793a56_JaffaCakes118

    • Size

      4.0MB

    • MD5

      26adc37442f43dd3e1c06c26c3793a56

    • SHA1

      15d6486f8c6c5c767651d3016624025d2fb34da4

    • SHA256

      f8ae2e6e1e607e7734fd02871d0754d7236e6f6ed9bb501ad6ff5115e40c42c2

    • SHA512

      55d21803162d126d460f95dccb580b85725a209a367a9ba00d00a5057370985bbd9a77689d7d45efb4ce7cec3b74edcaecd33f4d9bba4c9f4e21c371a8cb3765

    • SSDEEP

      98304:MRhxs1zO9FSSVNSt0RzOtk0kCkBptwhBKB0F+w7:GxEO9gSLSt0Ryi0pkBp6rK21

    • Modifies WinLogon for persistence

    • Modifies Windows Firewall

    • Sets service image path in registry

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Boot or Logon Autostart Execution

3
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Winlogon Helper DLL

1
T1547.004

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Boot or Logon Autostart Execution

3
T1547

Registry Run Keys / Startup Folder

2
T1547.001

Winlogon Helper DLL

1
T1547.004

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Defense Evasion

Modify Registry

3
T1112

Impair Defenses

1
T1562

Disable or Modify System Firewall

1
T1562.004

Tasks