General
-
Target
JaffaCakes118_01ae6cf6829a1eed952cf33a093f11fa
-
Size
108KB
-
Sample
250511-g6fkhagk7z
-
MD5
01ae6cf6829a1eed952cf33a093f11fa
-
SHA1
5fbf3b284ab5b38d981f9de6adb6987d30d5019f
-
SHA256
84f32905916d51dd011e0df8f98cc934b523a03b087cdf6b809659ec03adaf39
-
SHA512
c9bfbfb4f00045177398646cf33081c839a366bc10bc52025d45c8e1724729f651452bd981e826696f0456deb3f31803a12ef7a21aa132b09d18360fa601a5f7
-
SSDEEP
1536:S2Inyi09OZGR2cFgd2w9UlAWethqqjb4zHZfBpa9nNAMDr6tSQZx1:pInyiMOaFg1Gq4W9nNAGqSI
Static task
static1
Behavioral task
behavioral1
Sample
JaffaCakes118_01ae6cf6829a1eed952cf33a093f11fa.exe
Resource
win10v2004-20250502-en
Malware Config
Extracted
C:\Users\Admin\Desktop\RESTORE_FILES_INFO.txt
http://sonarmsniko2lvfu.onion
Targets
-
-
Target
JaffaCakes118_01ae6cf6829a1eed952cf33a093f11fa
-
Size
108KB
-
MD5
01ae6cf6829a1eed952cf33a093f11fa
-
SHA1
5fbf3b284ab5b38d981f9de6adb6987d30d5019f
-
SHA256
84f32905916d51dd011e0df8f98cc934b523a03b087cdf6b809659ec03adaf39
-
SHA512
c9bfbfb4f00045177398646cf33081c839a366bc10bc52025d45c8e1724729f651452bd981e826696f0456deb3f31803a12ef7a21aa132b09d18360fa601a5f7
-
SSDEEP
1536:S2Inyi09OZGR2cFgd2w9UlAWethqqjb4zHZfBpa9nNAMDr6tSQZx1:pInyiMOaFg1Gq4W9nNAGqSI
-
Disables service(s)
-
Modifies Windows Defender Real-time Protection settings
-
Renames multiple (52) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Modifies Windows Firewall
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Drops startup file
-
Executes dropped EXE
-
Loads dropped DLL
-
Modifies file permissions
-
Windows security modification
-
MITRE ATT&CK Enterprise v16
Persistence
Create or Modify System Process
5Windows Service
5Event Triggered Execution
1Netsh Helper DLL
1Privilege Escalation
Create or Modify System Process
5Windows Service
5Event Triggered Execution
1Netsh Helper DLL
1Defense Evasion
File and Directory Permissions Modification
1Impair Defenses
5Disable or Modify System Firewall
1Disable or Modify Tools
4Modify Registry
6Discovery
Network Service Discovery
1Network Share Discovery
1Peripheral Device Discovery
1Query Registry
2Remote System Discovery
2System Information Discovery
3System Location Discovery
1System Language Discovery
1System Network Configuration Discovery
1Internet Connection Discovery
1