General

  • Target

    188153f381a3b62bad11dd2f6ea6b498_JaffaCakes118

  • Size

    302KB

  • Sample

    240628-c85j7azcrj

  • MD5

    188153f381a3b62bad11dd2f6ea6b498

  • SHA1

    1468ddf7ad4464c787e216bf3a2f6a8f9e454778

  • SHA256

    568bb20f086c3b66c94ac2bdc7bff91d5452d118aebe74d81dfdd70633e6ab50

  • SHA512

    4dd529ba660261eedc5a152dd7cca11a2033440579f273f1edea2ff2ac882b8e6d6962450e29d702ff0e91725f8d407cb8d3d7db2b3b6139737b49f248726686

  • SSDEEP

    6144:3q3W2JBfvGQopEnL3L+Z4i14RjzgKQQI697orKOYwUiJ+KRH0NNe3:6NopoLKZx1U9QssrswUYRHye3

Malware Config

Targets

    • Target

      188153f381a3b62bad11dd2f6ea6b498_JaffaCakes118

    • Size

      302KB

    • MD5

      188153f381a3b62bad11dd2f6ea6b498

    • SHA1

      1468ddf7ad4464c787e216bf3a2f6a8f9e454778

    • SHA256

      568bb20f086c3b66c94ac2bdc7bff91d5452d118aebe74d81dfdd70633e6ab50

    • SHA512

      4dd529ba660261eedc5a152dd7cca11a2033440579f273f1edea2ff2ac882b8e6d6962450e29d702ff0e91725f8d407cb8d3d7db2b3b6139737b49f248726686

    • SSDEEP

      6144:3q3W2JBfvGQopEnL3L+Z4i14RjzgKQQI697orKOYwUiJ+KRH0NNe3:6NopoLKZx1U9QssrswUYRHye3

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Server Software Component: Terminal Services DLL

    • Deletes itself

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

System Information Discovery

1
T1082

Tasks