General

  • Target

    19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118

  • Size

    181KB

  • Sample

    240628-lfk5hsvemp

  • MD5

    19a049119999ce6179a6f2c7f1bc2cc3

  • SHA1

    9d69bfb8c0522f626dac62a2642b6488af30da41

  • SHA256

    90260fb517aef90268e0f95a4cfef939887f5acbd9448b2a291a93e65d13c1cb

  • SHA512

    8d6e9e2026ec4f57f16dee83ab2b0cdeb7cf4c5acc8e1c1a17824555c0855dc16313f79ef0887f341d13df664978baa06d7f96fe087b5ea5c668431d12244de0

  • SSDEEP

    3072:bLH3Qp/pHocucy4+qpbHiNeC2uEtcBVdI243cG1plubZCpg9CEP9o2ullx5cK5w:v6IcwTqpbiNeC3I/m8oCEyZlaKy

Malware Config

Targets

    • Target

      19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118

    • Size

      181KB

    • MD5

      19a049119999ce6179a6f2c7f1bc2cc3

    • SHA1

      9d69bfb8c0522f626dac62a2642b6488af30da41

    • SHA256

      90260fb517aef90268e0f95a4cfef939887f5acbd9448b2a291a93e65d13c1cb

    • SHA512

      8d6e9e2026ec4f57f16dee83ab2b0cdeb7cf4c5acc8e1c1a17824555c0855dc16313f79ef0887f341d13df664978baa06d7f96fe087b5ea5c668431d12244de0

    • SSDEEP

      3072:bLH3Qp/pHocucy4+qpbHiNeC2uEtcBVdI243cG1plubZCpg9CEP9o2ullx5cK5w:v6IcwTqpbiNeC3I/m8oCEyZlaKy

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • Modifies visiblity of hidden/system files in Explorer

    • ModiLoader Second Stage

    • Drops file in Drivers directory

    • Deletes itself

    • Loads dropped DLL

    • Modifies WinLogon

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Modify Registry

2
T1112

Tasks