General

  • Target

    1774ece535ca992eb08829fad9e4ff4d_JaffaCakes118

  • Size

    1.4MB

  • Sample

    240627-zh4ljascpk

  • MD5

    1774ece535ca992eb08829fad9e4ff4d

  • SHA1

    d2b6276dca11f949e7792823c5f3de5e965ae637

  • SHA256

    d5a3399d636e34cdccf1f27e39ee7339019fb08238c4859c99780835d51af02e

  • SHA512

    dcad9eacb1d34c1d5825146a83ff3f64d0b5d1835eefc1a51b591e892dd23dd2fda8de31298432f4bb7fdb04ca2a44b2c20ca8e3741e89a604ebb54a741c13dd

  • SSDEEP

    24576:84qyv4kEBdot9V1HTbynoOVb5Uq/jVDF9lAX2KN5WMjEAB87jiNL1Brc2u:lEv0txHnmdDRDF9lC2GgoWjiL1BG

Malware Config

Targets

    • Target

      1774ece535ca992eb08829fad9e4ff4d_JaffaCakes118

    • Size

      1.4MB

    • MD5

      1774ece535ca992eb08829fad9e4ff4d

    • SHA1

      d2b6276dca11f949e7792823c5f3de5e965ae637

    • SHA256

      d5a3399d636e34cdccf1f27e39ee7339019fb08238c4859c99780835d51af02e

    • SHA512

      dcad9eacb1d34c1d5825146a83ff3f64d0b5d1835eefc1a51b591e892dd23dd2fda8de31298432f4bb7fdb04ca2a44b2c20ca8e3741e89a604ebb54a741c13dd

    • SSDEEP

      24576:84qyv4kEBdot9V1HTbynoOVb5Uq/jVDF9lAX2KN5WMjEAB87jiNL1Brc2u:lEv0txHnmdDRDF9lC2GgoWjiL1BG

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • UAC bypass

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Checks whether UAC is enabled

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

3
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

3
T1082

Tasks