General

  • Target

    19dc3a57ed03c603c7da981158a8e8a4_JaffaCakes118

  • Size

    203KB

  • Sample

    240628-m1jymawanf

  • MD5

    19dc3a57ed03c603c7da981158a8e8a4

  • SHA1

    04016028516db80bc9f8dc3824aa175c8852da13

  • SHA256

    2cf0f0256f20b1971392fadcee01d37280693338c0aaf82cda02db47bf2fc050

  • SHA512

    a21112cea09493daf31ec0f089c94fe9b5a0b01e088bfb4eb8031cea74b8018e7a6bdd01f954409f30cabc2cd70e292d998e77eb339688c41f6993b0d86fd462

  • SSDEEP

    6144:cGtD2qOgIEx3VrzGGvySj3bMYwu68lzr1:nx1nPVon8lt

Malware Config

Targets

    • Target

      19dc3a57ed03c603c7da981158a8e8a4_JaffaCakes118

    • Size

      203KB

    • MD5

      19dc3a57ed03c603c7da981158a8e8a4

    • SHA1

      04016028516db80bc9f8dc3824aa175c8852da13

    • SHA256

      2cf0f0256f20b1971392fadcee01d37280693338c0aaf82cda02db47bf2fc050

    • SHA512

      a21112cea09493daf31ec0f089c94fe9b5a0b01e088bfb4eb8031cea74b8018e7a6bdd01f954409f30cabc2cd70e292d998e77eb339688c41f6993b0d86fd462

    • SSDEEP

      6144:cGtD2qOgIEx3VrzGGvySj3bMYwu68lzr1:nx1nPVon8lt

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Server Software Component: Terminal Services DLL

    • Deletes itself

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

System Information Discovery

1
T1082

Tasks