General

  • Target

    19e81e0a521ec0ce0608cd855796512c_JaffaCakes118

  • Size

    51KB

  • Sample

    240628-nbpcgsygnr

  • MD5

    19e81e0a521ec0ce0608cd855796512c

  • SHA1

    e403727a1d0b1eae0a697142b55dcb621f8539fe

  • SHA256

    d6346d093c870ad5274cb12973792c096acbefc5be33974039a5eaa2f922670d

  • SHA512

    48ce49918781247f351ab60e041c681c94e64eacd4520c38d4ba9fc59240f2bb4cddc136818ef516f9bd370ab16084eb91749eabde209404212c1b63a4d8a486

  • SSDEEP

    768:u+9LZQAX5ZPpO/5eR6N+Nw6bDr9+JGDO9iX8OSuLDIjBN8LOPMJafST2rs4Kjag4:V3Z6N+NTb/cGVSQ0b8LOPMJNEshjN4

Score
10/10

Malware Config

Targets

    • Target

      19e81e0a521ec0ce0608cd855796512c_JaffaCakes118

    • Size

      51KB

    • MD5

      19e81e0a521ec0ce0608cd855796512c

    • SHA1

      e403727a1d0b1eae0a697142b55dcb621f8539fe

    • SHA256

      d6346d093c870ad5274cb12973792c096acbefc5be33974039a5eaa2f922670d

    • SHA512

      48ce49918781247f351ab60e041c681c94e64eacd4520c38d4ba9fc59240f2bb4cddc136818ef516f9bd370ab16084eb91749eabde209404212c1b63a4d8a486

    • SSDEEP

      768:u+9LZQAX5ZPpO/5eR6N+Nw6bDr9+JGDO9iX8OSuLDIjBN8LOPMJafST2rs4Kjag4:V3Z6N+NTb/cGVSQ0b8LOPMJNEshjN4

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks