General

  • Target

    261060bbe68fe549e19c17f976c88dda_JaffaCakes118

  • Size

    20KB

  • Sample

    240704-ymzmpswbrl

  • MD5

    261060bbe68fe549e19c17f976c88dda

  • SHA1

    d3db286137ae2099df8f77ab5312b76970470aa7

  • SHA256

    b61c47836c8b2ed0663901884610e98d2a158a26f3a586ce99718dba283c7401

  • SHA512

    97bd63e7d13ffd38ea1e2c6d8e6fadda96fb35505e9365cea32877848045725dca9ea5b5b4bed9e864ceb4def9d0363d4041b77a159e24cdafcc643491dd0241

  • SSDEEP

    384:WQIRLeWCRjf9PJQ9/SZGuNgSlQEzEhymEo611IPw0AoAAxgr6+S9Pfu7n5Y:W38WCRjffQdBu5lQCho6PI8oLxHdeVY

Score
10/10

Malware Config

Targets

    • Target

      261060bbe68fe549e19c17f976c88dda_JaffaCakes118

    • Size

      20KB

    • MD5

      261060bbe68fe549e19c17f976c88dda

    • SHA1

      d3db286137ae2099df8f77ab5312b76970470aa7

    • SHA256

      b61c47836c8b2ed0663901884610e98d2a158a26f3a586ce99718dba283c7401

    • SHA512

      97bd63e7d13ffd38ea1e2c6d8e6fadda96fb35505e9365cea32877848045725dca9ea5b5b4bed9e864ceb4def9d0363d4041b77a159e24cdafcc643491dd0241

    • SSDEEP

      384:WQIRLeWCRjf9PJQ9/SZGuNgSlQEzEhymEo611IPw0AoAAxgr6+S9Pfu7n5Y:W38WCRjffQdBu5lQCho6PI8oLxHdeVY

    Score
    10/10
    • Modifies security service

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks