General

  • Target

    197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118

  • Size

    318KB

  • Sample

    240628-klxvtszgrd

  • MD5

    197d1cfaf6212a21eabba8a7dff2cc23

  • SHA1

    968707b044e72aec108b107b75aa3f05f5f383e6

  • SHA256

    035dcab3a8e6b5f616e76276e0ecbb9d6ef86f9e2459583f39c1df1557047281

  • SHA512

    eb212919186bc8e42b180905ce6f3cf5d3cf31a0aa998fc56ba5259e5f1e24b2cb6f78adbb37c8dfde0ce624250c6ae9c1730180e1cfb62be41b4cdd9c78d170

  • SSDEEP

    6144:KSg2/gq1hK2naL0MnICv2t5ckoFaf9c21LMluIH/pP:Lg2YqWX0iICcWJFaW2lMluIH

Malware Config

Targets

    • Target

      197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118

    • Size

      318KB

    • MD5

      197d1cfaf6212a21eabba8a7dff2cc23

    • SHA1

      968707b044e72aec108b107b75aa3f05f5f383e6

    • SHA256

      035dcab3a8e6b5f616e76276e0ecbb9d6ef86f9e2459583f39c1df1557047281

    • SHA512

      eb212919186bc8e42b180905ce6f3cf5d3cf31a0aa998fc56ba5259e5f1e24b2cb6f78adbb37c8dfde0ce624250c6ae9c1730180e1cfb62be41b4cdd9c78d170

    • SSDEEP

      6144:KSg2/gq1hK2naL0MnICv2t5ckoFaf9c21LMluIH/pP:Lg2YqWX0iICcWJFaW2lMluIH

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader First Stage

    • Loads dropped DLL

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks