General

  • Target

    159e9824fb106c09042adc167d282d29_JaffaCakes118

  • Size

    405KB

  • Sample

    240627-l9vaaaycrq

  • MD5

    159e9824fb106c09042adc167d282d29

  • SHA1

    bca18b9b043d9e060ecd390ae807efb18266ee8d

  • SHA256

    aab3211eef5c876eb99106878ba63c29b05fa968b44b4a5c10977ccdcf4d12f6

  • SHA512

    57a11eaaa7d470fe7d8a5e75d5e1d1511dcefe7421c802fb295a308f81654fb0f09240e24f9104ea3ddd4d908114d6a4ac01e4d5feb215ccb841d4644f0c962b

  • SSDEEP

    6144:ydw6ZYyddSLWuM9w8MOnrjAHlNEsBz7L2293x8f5SoPDk8KFtEDrp9SVUKg93HYv:iZdTnF1nqaYz7Rgo86EDlo

Malware Config

Targets

    • Target

      159e9824fb106c09042adc167d282d29_JaffaCakes118

    • Size

      405KB

    • MD5

      159e9824fb106c09042adc167d282d29

    • SHA1

      bca18b9b043d9e060ecd390ae807efb18266ee8d

    • SHA256

      aab3211eef5c876eb99106878ba63c29b05fa968b44b4a5c10977ccdcf4d12f6

    • SHA512

      57a11eaaa7d470fe7d8a5e75d5e1d1511dcefe7421c802fb295a308f81654fb0f09240e24f9104ea3ddd4d908114d6a4ac01e4d5feb215ccb841d4644f0c962b

    • SSDEEP

      6144:ydw6ZYyddSLWuM9w8MOnrjAHlNEsBz7L2293x8f5SoPDk8KFtEDrp9SVUKg93HYv:iZdTnF1nqaYz7Rgo86EDlo

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Event Triggered Execution: Image File Execution Options Injection

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Image File Execution Options Injection

1
T1546.012

Privilege Escalation

Event Triggered Execution

1
T1546

Image File Execution Options Injection

1
T1546.012

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks