General

  • Target

    JaffaCakes118_01aaec33b8dbbe813042c11093b8115e

  • Size

    74KB

  • Sample

    250511-gksmyawsdy

  • MD5

    01aaec33b8dbbe813042c11093b8115e

  • SHA1

    5a3517ff24a75e264787f190bf58ca2b6f306f31

  • SHA256

    1dd233eb82d0072e21eaaac0bf192c88e7815014d319e5c71cf4cb18ff82ae83

  • SHA512

    6271eedda22dbd23152c4e7c85580659309125c1c034fe7baf8d3c169264bc8f989f82041164f4fc0910a8c1746f65d4a60a6195e918d2c768f474d8706e4f16

  • SSDEEP

    1536:exxEd/8Sq5m51ayHwkVR4TIfgu84JkHRjMEDrZin7LS5DoB:eHEN71aI47xjMY9GLQoB

Malware Config

Targets

    • Target

      JaffaCakes118_01aaec33b8dbbe813042c11093b8115e

    • Size

      74KB

    • MD5

      01aaec33b8dbbe813042c11093b8115e

    • SHA1

      5a3517ff24a75e264787f190bf58ca2b6f306f31

    • SHA256

      1dd233eb82d0072e21eaaac0bf192c88e7815014d319e5c71cf4cb18ff82ae83

    • SHA512

      6271eedda22dbd23152c4e7c85580659309125c1c034fe7baf8d3c169264bc8f989f82041164f4fc0910a8c1746f65d4a60a6195e918d2c768f474d8706e4f16

    • SSDEEP

      1536:exxEd/8Sq5m51ayHwkVR4TIfgu84JkHRjMEDrZin7LS5DoB:eHEN71aI47xjMY9GLQoB

    • Modifies Windows Firewall

    • Executes dropped EXE

    • Unexpected DNS network traffic destination

      Network traffic to other servers than the configured DNS servers was detected on the DNS port.

    • Indicator Removal: File Deletion

      Adversaries may delete files left behind by the actions of their intrusion activity.

    • Drops file in System32 directory

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »