General

  • Target

    19224d8fe2957721118d14faef5096ce_JaffaCakes118

  • Size

    68KB

  • Sample

    240628-hb5ftayclp

  • MD5

    19224d8fe2957721118d14faef5096ce

  • SHA1

    2438ee98bc8a07143c6e64c7a1bcb1386878baa3

  • SHA256

    fb4aef1c345a246ca40f7629e3a760a69e7a84161995286cda1fd26aa74c3ae9

  • SHA512

    867d2e0d94ab71c4d6eb2ec9df1c79ebbca8b6d3db8c0f58cf27bb1ea852c0caed39fe058f0ed194df41354177881ee2d8ae4d9c59b10c3afbcb17a3425833de

  • SSDEEP

    1536:p4jqi5axwdaPpyNlDgS54QuZxDuKTVWCrx4LTT61B8:ujpaxGaPpyNV54DyiVd12

Score
10/10

Malware Config

Targets

    • Target

      19224d8fe2957721118d14faef5096ce_JaffaCakes118

    • Size

      68KB

    • MD5

      19224d8fe2957721118d14faef5096ce

    • SHA1

      2438ee98bc8a07143c6e64c7a1bcb1386878baa3

    • SHA256

      fb4aef1c345a246ca40f7629e3a760a69e7a84161995286cda1fd26aa74c3ae9

    • SHA512

      867d2e0d94ab71c4d6eb2ec9df1c79ebbca8b6d3db8c0f58cf27bb1ea852c0caed39fe058f0ed194df41354177881ee2d8ae4d9c59b10c3afbcb17a3425833de

    • SSDEEP

      1536:p4jqi5axwdaPpyNlDgS54QuZxDuKTVWCrx4LTT61B8:ujpaxGaPpyNV54DyiVd12

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks