General

  • Target

    19e08011fb339f18cbb5d2c2c85db3a6_JaffaCakes118

  • Size

    44KB

  • Sample

    240628-m4yk7awcjh

  • MD5

    19e08011fb339f18cbb5d2c2c85db3a6

  • SHA1

    c7f2ff109124c4fcd12c1578da3ec07d0061644f

  • SHA256

    5a65e6273b9245dca62c3b5ccb748fb53898827074f3f2609ba9b39ea3e1cedb

  • SHA512

    e67eae6681499334394f9a68baea629c8c8510f23dd129dffa644ea702f797aae23890af42a3b43390860f9f61c41968fdaf768fb5b01fc99b8b0d4a9eb1d0d1

  • SSDEEP

    768:TzB4YaZ6uCKMrsRP1kQOvi7Q7uWPFz0EJ0PtuOi68FD7X9M9s8ecZuff/Ym6/IB4:TCYaZ9hRP8vi74FgEJ017i9FnONAfYmE

Score
10/10

Malware Config

Targets

    • Target

      19e08011fb339f18cbb5d2c2c85db3a6_JaffaCakes118

    • Size

      44KB

    • MD5

      19e08011fb339f18cbb5d2c2c85db3a6

    • SHA1

      c7f2ff109124c4fcd12c1578da3ec07d0061644f

    • SHA256

      5a65e6273b9245dca62c3b5ccb748fb53898827074f3f2609ba9b39ea3e1cedb

    • SHA512

      e67eae6681499334394f9a68baea629c8c8510f23dd129dffa644ea702f797aae23890af42a3b43390860f9f61c41968fdaf768fb5b01fc99b8b0d4a9eb1d0d1

    • SSDEEP

      768:TzB4YaZ6uCKMrsRP1kQOvi7Q7uWPFz0EJ0PtuOi68FD7X9M9s8ecZuff/Ym6/IB4:TCYaZ9hRP8vi74FgEJ017i9FnONAfYmE

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Drops file in Drivers directory

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

2
T1112

Discovery

System Information Discovery

1
T1082

Tasks