General

  • Target

    19c9ac3ad43cfef8c4a5cf3640f6194f_JaffaCakes118

  • Size

    690KB

  • Sample

    240628-mhqnfsvaqc

  • MD5

    19c9ac3ad43cfef8c4a5cf3640f6194f

  • SHA1

    b256386cdf83edc56fa76cf0e8828c3b62991c51

  • SHA256

    da40cf61eee19f3a427e9697956aa7af9a46c942461795bef1aa3dd385d4ad44

  • SHA512

    e75308831ed8d5e7ab24b0d122775d966b9d8dfd7ddcfaff57b6615623d7558b9b1b6d89a28051188f6b220c3633e0c8af0a8fbcc01cabdd6087c6689ee00b71

  • SSDEEP

    12288:0dtGgozqi5paO0lp9USQVUSyrkA4zZ6J+v5NdTgxWaSTAzG:m2eas1USImazIwPuIaSToG

Score
10/10

Malware Config

Targets

    • Target

      19c9ac3ad43cfef8c4a5cf3640f6194f_JaffaCakes118

    • Size

      690KB

    • MD5

      19c9ac3ad43cfef8c4a5cf3640f6194f

    • SHA1

      b256386cdf83edc56fa76cf0e8828c3b62991c51

    • SHA256

      da40cf61eee19f3a427e9697956aa7af9a46c942461795bef1aa3dd385d4ad44

    • SHA512

      e75308831ed8d5e7ab24b0d122775d966b9d8dfd7ddcfaff57b6615623d7558b9b1b6d89a28051188f6b220c3633e0c8af0a8fbcc01cabdd6087c6689ee00b71

    • SSDEEP

      12288:0dtGgozqi5paO0lp9USQVUSyrkA4zZ6J+v5NdTgxWaSTAzG:m2eas1USImazIwPuIaSToG

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

2
T1012

System Information Discovery

1
T1082

Tasks