General

  • Target

    1a7f966efc28f7db47e99f4cad688a5e_JaffaCakes118

  • Size

    282KB

  • Sample

    240701-jpkh8szdqh

  • MD5

    1a7f966efc28f7db47e99f4cad688a5e

  • SHA1

    315556a44bf5937cb4c031c06e733cd0ea87b475

  • SHA256

    660ba8f32c96a618aa9e8ee472a742564a0dd02d4dc1ce4131dfc36ab1a52c0c

  • SHA512

    32af17f6157c2523160691f06299ccd6c670f03ffac01eac57c1f398eb04b8b7452889df9704a7089382a0bd6112c100f0d3dbe0c5f5cbe6e4e4c18f64afb048

  • SSDEEP

    6144:h8X1kpAxaXKXKwg0Uop6e+EGGB7JolHqN3x6km0r:il0AxaX/if6BocHY3r

Malware Config

Targets

    • Target

      1a7f966efc28f7db47e99f4cad688a5e_JaffaCakes118

    • Size

      282KB

    • MD5

      1a7f966efc28f7db47e99f4cad688a5e

    • SHA1

      315556a44bf5937cb4c031c06e733cd0ea87b475

    • SHA256

      660ba8f32c96a618aa9e8ee472a742564a0dd02d4dc1ce4131dfc36ab1a52c0c

    • SHA512

      32af17f6157c2523160691f06299ccd6c670f03ffac01eac57c1f398eb04b8b7452889df9704a7089382a0bd6112c100f0d3dbe0c5f5cbe6e4e4c18f64afb048

    • SSDEEP

      6144:h8X1kpAxaXKXKwg0Uop6e+EGGB7JolHqN3x6km0r:il0AxaX/if6BocHY3r

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops autorun.inf file

      Malware can abuse Windows Autorun to spread further via attached volumes.

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Initial Access

Replication Through Removable Media

1
T1091

Persistence

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Privilege Escalation

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Lateral Movement

Replication Through Removable Media

1
T1091

Tasks