General

  • Target

    178bfbc47f1a00b54b84d5d7212a9c1f_JaffaCakes118

  • Size

    139KB

  • Sample

    240627-z2hs6stcqr

  • MD5

    178bfbc47f1a00b54b84d5d7212a9c1f

  • SHA1

    3630547cd03382308ad3517220b5f7bf59be11c5

  • SHA256

    1cf07e726eddce3d3866d6170b440e23b5e0cd867b41e3a4bc17c482a3f1ed63

  • SHA512

    5bc71bbbb842bb94d272ed7f609c9ee13dcbb0da8ee0273d99e8e60e2cb731c947172c507b0b708f30cb636edbbac0d5f014f04deb8f252f632fec600974642d

  • SSDEEP

    3072:qwpEg9z1MSU2l04B9SdZpa7QnYPLb+90j3YGgB/6W3Lqw:qy1MSjC4vS0EQ20jIGgF6W3Lqw

Malware Config

Targets

    • Target

      178bfbc47f1a00b54b84d5d7212a9c1f_JaffaCakes118

    • Size

      139KB

    • MD5

      178bfbc47f1a00b54b84d5d7212a9c1f

    • SHA1

      3630547cd03382308ad3517220b5f7bf59be11c5

    • SHA256

      1cf07e726eddce3d3866d6170b440e23b5e0cd867b41e3a4bc17c482a3f1ed63

    • SHA512

      5bc71bbbb842bb94d272ed7f609c9ee13dcbb0da8ee0273d99e8e60e2cb731c947172c507b0b708f30cb636edbbac0d5f014f04deb8f252f632fec600974642d

    • SSDEEP

      3072:qwpEg9z1MSU2l04B9SdZpa7QnYPLb+90j3YGgB/6W3Lqw:qy1MSjC4vS0EQ20jIGgF6W3Lqw

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • UAC bypass

    • ModiLoader Second Stage

    • Loads dropped DLL

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

2
T1112

Discovery

System Information Discovery

1
T1082

Tasks