General

  • Target

    1aa56bd6a61b14b8f2a2445ddb8166b0_JaffaCakes118

  • Size

    297KB

  • Sample

    240701-kmqg5ssarf

  • MD5

    1aa56bd6a61b14b8f2a2445ddb8166b0

  • SHA1

    6be0da4bb45c149c61aa758ef6302bc1f9825f17

  • SHA256

    6d7a05a939aa32e8b0ae68d271b4e7695a53261e5fef832d8383e6fd8eb5ca93

  • SHA512

    56d562292cad7b35c2e09a8a2fd90c38460ea1d69a7cf6f4c8775fc9d965e40666400515ef7a5e48082b1bf4d25ccdefc4b0c71b45b2ab17134a4ee56cc8c31a

  • SSDEEP

    6144:JwVgfBuCF6vJBpuQiEdsgVwufvUkvKoC5BnQejdK:UCF6vJBpDvG5zv8

Malware Config

Targets

    • Target

      1aa56bd6a61b14b8f2a2445ddb8166b0_JaffaCakes118

    • Size

      297KB

    • MD5

      1aa56bd6a61b14b8f2a2445ddb8166b0

    • SHA1

      6be0da4bb45c149c61aa758ef6302bc1f9825f17

    • SHA256

      6d7a05a939aa32e8b0ae68d271b4e7695a53261e5fef832d8383e6fd8eb5ca93

    • SHA512

      56d562292cad7b35c2e09a8a2fd90c38460ea1d69a7cf6f4c8775fc9d965e40666400515ef7a5e48082b1bf4d25ccdefc4b0c71b45b2ab17134a4ee56cc8c31a

    • SSDEEP

      6144:JwVgfBuCF6vJBpuQiEdsgVwufvUkvKoC5BnQejdK:UCF6vJBpDvG5zv8

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Server Software Component: Terminal Services DLL

    • Deletes itself

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Tasks