General

  • Target

    19d1b91ef29c24381721b9ebbf4af89e_JaffaCakes118

  • Size

    223KB

  • Sample

    240628-mq534svele

  • MD5

    19d1b91ef29c24381721b9ebbf4af89e

  • SHA1

    61986c04e63dcda4716c3f0e0b8b880eb4bde687

  • SHA256

    acc8873a23ff9a6a2b234faf2faea7e42c690277f6fdbc45b31ebab4a383e08a

  • SHA512

    745f1d8feb8540ef1d17eaa8df920517bdcd7e36db4d318d691bc5550926089acb8c43a1603a2b4acb7d434de998dfaca3e151af20efd10110f885f10a229a85

  • SSDEEP

    6144:TebAeX4/K5RthYZl1OmdqcTnixNjpTAoS1:TuI/IwlzdqpxJ+oS1

Malware Config

Targets

    • Target

      19d1b91ef29c24381721b9ebbf4af89e_JaffaCakes118

    • Size

      223KB

    • MD5

      19d1b91ef29c24381721b9ebbf4af89e

    • SHA1

      61986c04e63dcda4716c3f0e0b8b880eb4bde687

    • SHA256

      acc8873a23ff9a6a2b234faf2faea7e42c690277f6fdbc45b31ebab4a383e08a

    • SHA512

      745f1d8feb8540ef1d17eaa8df920517bdcd7e36db4d318d691bc5550926089acb8c43a1603a2b4acb7d434de998dfaca3e151af20efd10110f885f10a229a85

    • SSDEEP

      6144:TebAeX4/K5RthYZl1OmdqcTnixNjpTAoS1:TuI/IwlzdqpxJ+oS1

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Adds Run key to start application

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks