General

  • Target

    1a31a98075704380eeff6383c9b69aed_JaffaCakes118

  • Size

    128KB

  • Sample

    240628-p5krtszhkf

  • MD5

    1a31a98075704380eeff6383c9b69aed

  • SHA1

    38625429e7fcd5c56bc6de606c82ccf966b31293

  • SHA256

    02ea40c6e298371e21888c2ba5a519a69a1e0b58a06ea4a70de0732e45ed0ad2

  • SHA512

    3441f933bb6baf7949684ad0d6ee421bdbc684be0b0ca7faef72aaca754458289e5bd21d3a8068faa750782c393a339fc26c07877a057434f68b15c3be0696cf

  • SSDEEP

    3072:M1cAIPWSxIkwx6+/+ZwzmR9Xtj1ihwz9UmqM+DX32whuP83hV:UcZjxIz6+/+ZwzGnWwG9hnBg0xV

Malware Config

Targets

    • Target

      1a31a98075704380eeff6383c9b69aed_JaffaCakes118

    • Size

      128KB

    • MD5

      1a31a98075704380eeff6383c9b69aed

    • SHA1

      38625429e7fcd5c56bc6de606c82ccf966b31293

    • SHA256

      02ea40c6e298371e21888c2ba5a519a69a1e0b58a06ea4a70de0732e45ed0ad2

    • SHA512

      3441f933bb6baf7949684ad0d6ee421bdbc684be0b0ca7faef72aaca754458289e5bd21d3a8068faa750782c393a339fc26c07877a057434f68b15c3be0696cf

    • SSDEEP

      3072:M1cAIPWSxIkwx6+/+ZwzmR9Xtj1ihwz9UmqM+DX32whuP83hV:UcZjxIz6+/+ZwzGnWwG9hnBg0xV

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

3
T1082

Tasks