General

  • Target

    260c70092043daf88b19af99ff9cbb36_JaffaCakes118

  • Size

    562KB

  • Sample

    240704-yjt8tayajf

  • MD5

    260c70092043daf88b19af99ff9cbb36

  • SHA1

    a9437cfef00e2603884990ea4d22c52eff3fbbc6

  • SHA256

    5b9d5188032d63c8d5638f28bdc1f9fae25182fe4bd6d089ffb7affc843e8c11

  • SHA512

    35f47a3e176210d220c75c6769202cfc0139fa63b155c79c9cd2d6c9715f9b2b2fc59f78ea10b3f2efab07f5cf35627d09678200432a32bf954d035bb54c4022

  • SSDEEP

    12288:5iyhC36BkA4d4qxwJ0fi3IYK5/7+XST5l:5i+C3OkIqxwJr3IYK5aXO5

Malware Config

Targets

    • Target

      260c70092043daf88b19af99ff9cbb36_JaffaCakes118

    • Size

      562KB

    • MD5

      260c70092043daf88b19af99ff9cbb36

    • SHA1

      a9437cfef00e2603884990ea4d22c52eff3fbbc6

    • SHA256

      5b9d5188032d63c8d5638f28bdc1f9fae25182fe4bd6d089ffb7affc843e8c11

    • SHA512

      35f47a3e176210d220c75c6769202cfc0139fa63b155c79c9cd2d6c9715f9b2b2fc59f78ea10b3f2efab07f5cf35627d09678200432a32bf954d035bb54c4022

    • SSDEEP

      12288:5iyhC36BkA4d4qxwJ0fi3IYK5/7+XST5l:5i+C3OkIqxwJr3IYK5aXO5

    • Server Software Component: Terminal Services DLL

    • ASPack v2.12-2.42

      Detects executables packed with ASPack v2.12-2.42

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Tasks