General
-
Target
1ad6d956edb032983569cb5826968704_JaffaCakes118
-
Size
1.3MB
-
Sample
240701-lwhpbsyamr
-
MD5
1ad6d956edb032983569cb5826968704
-
SHA1
2488741528813b42010d51990547c1f3389c5a3a
-
SHA256
571303a43aaf1fa5fc24268abcf4c1095676b3d20372396441b6aa13d62f4231
-
SHA512
e99f0a3e793734b00a15b353fb0fd78955775d8882150d134e38504c58aa416a42eb7196a220c2d226d86035d55443152da1e68abbd464f6867b7b80250a64a1
-
SSDEEP
24576:TlJaw9jzEEgY+xDTLxD/iyfSviNT3JfgpwpNyXoLis5DSMjgzES4Fo+43+d:TlJao0DTtD/jqKNhXyXhQDSMOf4
Behavioral task
behavioral1
Sample
1ad6d956edb032983569cb5826968704_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1ad6d956edb032983569cb5826968704_JaffaCakes118.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
1ad6d956edb032983569cb5826968704_JaffaCakes118
-
Size
1.3MB
-
MD5
1ad6d956edb032983569cb5826968704
-
SHA1
2488741528813b42010d51990547c1f3389c5a3a
-
SHA256
571303a43aaf1fa5fc24268abcf4c1095676b3d20372396441b6aa13d62f4231
-
SHA512
e99f0a3e793734b00a15b353fb0fd78955775d8882150d134e38504c58aa416a42eb7196a220c2d226d86035d55443152da1e68abbd464f6867b7b80250a64a1
-
SSDEEP
24576:TlJaw9jzEEgY+xDTLxD/iyfSviNT3JfgpwpNyXoLis5DSMjgzES4Fo+43+d:TlJao0DTtD/jqKNhXyXhQDSMOf4
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Deletes itself
-
Executes dropped EXE
-
Adds Run key to start application
-
MITRE ATT&CK Matrix ATT&CK v13
Privilege Escalation
Abuse Elevation Control Mechanism
1Bypass User Account Control
1Boot or Logon Autostart Execution
1Registry Run Keys / Startup Folder
1