Analysis
-
max time kernel
118s -
max time network
119s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 09:08
Behavioral task
behavioral1
Sample
1ab61af630d5e833295d9935805e489f_JaffaCakes118.dll
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
1ab61af630d5e833295d9935805e489f_JaffaCakes118.dll
Resource
win10v2004-20240226-en
General
-
Target
1ab61af630d5e833295d9935805e489f_JaffaCakes118.dll
-
Size
150KB
-
MD5
1ab61af630d5e833295d9935805e489f
-
SHA1
05d975657c6327cd5827005c2e284cb544b8cebd
-
SHA256
d6a597733125393fabb52f705c18a0ea17c1038ee94db30285fc55a45fe54ff2
-
SHA512
76b182d0c7ff585e01b7193c643b3abcd913876b35a18aecad2fc166096f18ae2edd32002ada13ac563359baef4343dfa1215b2d64424c418bd325dc470dbb63
-
SSDEEP
1536:BAqMQ2mieCvDHMcviHCj/uLRClBfb7puP+HgSD:2PTRDHjQLRgBfblVpD
Malware Config
Signatures
-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage 1 IoCs
Processes:
resource yara_rule behavioral1/memory/2076-0-0x0000000000400000-0x0000000000425000-memory.dmp modiloader_stage2 -
Suspicious use of WriteProcessMemory 7 IoCs
Processes:
regsvr32.exedescription pid process target process PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe PID 1752 wrote to memory of 2076 1752 regsvr32.exe regsvr32.exe
Processes
-
C:\Windows\system32\regsvr32.exeregsvr32 /s C:\Users\Admin\AppData\Local\Temp\1ab61af630d5e833295d9935805e489f_JaffaCakes118.dll1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\regsvr32.exe/s C:\Users\Admin\AppData\Local\Temp\1ab61af630d5e833295d9935805e489f_JaffaCakes118.dll2⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2076-0-0x0000000000400000-0x0000000000425000-memory.dmpFilesize
148KB