General

  • Target

    1ad6d956edb032983569cb5826968704_JaffaCakes118

  • Size

    1.3MB

  • Sample

    240701-lwhpbsyamr

  • MD5

    1ad6d956edb032983569cb5826968704

  • SHA1

    2488741528813b42010d51990547c1f3389c5a3a

  • SHA256

    571303a43aaf1fa5fc24268abcf4c1095676b3d20372396441b6aa13d62f4231

  • SHA512

    e99f0a3e793734b00a15b353fb0fd78955775d8882150d134e38504c58aa416a42eb7196a220c2d226d86035d55443152da1e68abbd464f6867b7b80250a64a1

  • SSDEEP

    24576:TlJaw9jzEEgY+xDTLxD/iyfSviNT3JfgpwpNyXoLis5DSMjgzES4Fo+43+d:TlJao0DTtD/jqKNhXyXhQDSMOf4

Malware Config

Targets

    • Target

      1ad6d956edb032983569cb5826968704_JaffaCakes118

    • Size

      1.3MB

    • MD5

      1ad6d956edb032983569cb5826968704

    • SHA1

      2488741528813b42010d51990547c1f3389c5a3a

    • SHA256

      571303a43aaf1fa5fc24268abcf4c1095676b3d20372396441b6aa13d62f4231

    • SHA512

      e99f0a3e793734b00a15b353fb0fd78955775d8882150d134e38504c58aa416a42eb7196a220c2d226d86035d55443152da1e68abbd464f6867b7b80250a64a1

    • SSDEEP

      24576:TlJaw9jzEEgY+xDTLxD/iyfSviNT3JfgpwpNyXoLis5DSMjgzES4Fo+43+d:TlJao0DTtD/jqKNhXyXhQDSMOf4

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • UAC bypass

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Adds Run key to start application

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

3
T1112

Discovery

System Information Discovery

2
T1082

Tasks