General

  • Target

    1b68c1b28122776e25be7d01e29aba23_JaffaCakes118

  • Size

    449KB

  • Sample

    240701-qbqawswgpk

  • MD5

    1b68c1b28122776e25be7d01e29aba23

  • SHA1

    aa865b99291d7630910ece3f956d32fec2626d85

  • SHA256

    dcadfd906850de7d6c5574d66fbef10485fdaa84429e7fb974f24cf0e9170a66

  • SHA512

    20f10c29a5a3ce56f4989cb946c1deb973f25a9c235f605999981cdf00c5b6d7b419b519c02bd3dee1df93513b996ba2b8ab491a3642c56f26cdfdf2dbbf35cb

  • SSDEEP

    12288:RMAOOl1nD7UHf5Zm46GByHmYetaIEWYRB3lpov:RrXncHf5k46MYmRaTWYdpo

Malware Config

Targets

    • Target

      1b68c1b28122776e25be7d01e29aba23_JaffaCakes118

    • Size

      449KB

    • MD5

      1b68c1b28122776e25be7d01e29aba23

    • SHA1

      aa865b99291d7630910ece3f956d32fec2626d85

    • SHA256

      dcadfd906850de7d6c5574d66fbef10485fdaa84429e7fb974f24cf0e9170a66

    • SHA512

      20f10c29a5a3ce56f4989cb946c1deb973f25a9c235f605999981cdf00c5b6d7b419b519c02bd3dee1df93513b996ba2b8ab491a3642c56f26cdfdf2dbbf35cb

    • SSDEEP

      12288:RMAOOl1nD7UHf5Zm46GByHmYetaIEWYRB3lpov:RrXncHf5k46MYmRaTWYdpo

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Drops autorun.inf file

      Malware can abuse Windows Autorun to spread further via attached volumes.

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Initial Access

Replication Through Removable Media

1
T1091

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Lateral Movement

Replication Through Removable Media

1
T1091

Tasks