General

  • Target

    1ac08f4c72120c70f805ff7d8db5088a_JaffaCakes118

  • Size

    671KB

  • Sample

    240701-lcetbstcph

  • MD5

    1ac08f4c72120c70f805ff7d8db5088a

  • SHA1

    0d68b32ba08cfc60a53f91c6d169bd5956d3bc98

  • SHA256

    1bf610a3b24c3e24971ec480028971474c74721d8d5dd4c75d34b5d482260630

  • SHA512

    ddc28acd248b51e3c6c8925fc2c0dc487872dc991c70ae921c401f6ac6d2927acc2bba8f92b538e70927064a237ec23cf1423cadadfec97fe811f7f2952f8b1e

  • SSDEEP

    12288:UrnItzSwZk14r5uT1j5EHnoH6FT+BCj4zcrg1c2obY7n/uLf7vK:Urn0Sw+muT9Ms6FTaCjprSocT/uvvK

Score
10/10

Malware Config

Targets

    • Target

      1ac08f4c72120c70f805ff7d8db5088a_JaffaCakes118

    • Size

      671KB

    • MD5

      1ac08f4c72120c70f805ff7d8db5088a

    • SHA1

      0d68b32ba08cfc60a53f91c6d169bd5956d3bc98

    • SHA256

      1bf610a3b24c3e24971ec480028971474c74721d8d5dd4c75d34b5d482260630

    • SHA512

      ddc28acd248b51e3c6c8925fc2c0dc487872dc991c70ae921c401f6ac6d2927acc2bba8f92b538e70927064a237ec23cf1423cadadfec97fe811f7f2952f8b1e

    • SSDEEP

      12288:UrnItzSwZk14r5uT1j5EHnoH6FT+BCj4zcrg1c2obY7n/uLf7vK:Urn0Sw+muT9Ms6FTaCjprSocT/uvvK

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops autorun.inf file

      Malware can abuse Windows Autorun to spread further via attached volumes.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Initial Access

Replication Through Removable Media

1
T1091

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Lateral Movement

Replication Through Removable Media

1
T1091

Tasks