General

  • Target

    167dbe17a709dc81f0bb07f05ad88b6e_JaffaCakes118

  • Size

    355KB

  • Sample

    240627-spxcgaxcqe

  • MD5

    167dbe17a709dc81f0bb07f05ad88b6e

  • SHA1

    b9383509de7d27430c71d1ece96d8854ac4e87d5

  • SHA256

    155fbbfbd00eaa3e1cb4b93f6b3943329d78cb4c6db46071ca745e3a63ce5112

  • SHA512

    f1bad85e85fd4e53f8757c17a72c6c8cac71e2d282d954618db4b920be3650e8dd8439c59927ac99cf0a2948a78576ce1a23ab7756c983d3ec6a17e70ead444c

  • SSDEEP

    6144:funQcTrYYk4770hrIily0yNsdmlXDEaYoDR59COnnK7t5P41fVHsNf4JKGSn:mQN4a1yNsAXDx5RnObAGN1v

Score
10/10

Malware Config

Targets

    • Target

      167dbe17a709dc81f0bb07f05ad88b6e_JaffaCakes118

    • Size

      355KB

    • MD5

      167dbe17a709dc81f0bb07f05ad88b6e

    • SHA1

      b9383509de7d27430c71d1ece96d8854ac4e87d5

    • SHA256

      155fbbfbd00eaa3e1cb4b93f6b3943329d78cb4c6db46071ca745e3a63ce5112

    • SHA512

      f1bad85e85fd4e53f8757c17a72c6c8cac71e2d282d954618db4b920be3650e8dd8439c59927ac99cf0a2948a78576ce1a23ab7756c983d3ec6a17e70ead444c

    • SSDEEP

      6144:funQcTrYYk4770hrIily0yNsdmlXDEaYoDR59COnnK7t5P41fVHsNf4JKGSn:mQN4a1yNsAXDx5RnObAGN1v

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks