General

  • Target

    1b740553ee4a960dd2c557a7447225a1_JaffaCakes118

  • Size

    379KB

  • Sample

    240701-qla9qaxckr

  • MD5

    1b740553ee4a960dd2c557a7447225a1

  • SHA1

    2e4a9ea89a0434fa75ac25fc02a22597ff6f4ba9

  • SHA256

    351be00614526c5dee37a1b157a124453be177b496039e461451e4eff475934a

  • SHA512

    1b0727ee1a27ae1ee60c4b349354af49b0ad1480b335299e4eb599f1421841c7b478d7f1938da2a368c5ffff2fc91e1fd658c561ccfbc57ffa6f48e4b9d9385f

  • SSDEEP

    6144:sefy8pQP0VuwLQ4sf0BDlirMDGgo5R7+s4E/wXDaCgRiFb4TUvBIBOXDAbzF:hyIQkY4s89lirMigi1N4VaCgAFbWUv6N

Malware Config

Targets

    • Target

      1b740553ee4a960dd2c557a7447225a1_JaffaCakes118

    • Size

      379KB

    • MD5

      1b740553ee4a960dd2c557a7447225a1

    • SHA1

      2e4a9ea89a0434fa75ac25fc02a22597ff6f4ba9

    • SHA256

      351be00614526c5dee37a1b157a124453be177b496039e461451e4eff475934a

    • SHA512

      1b0727ee1a27ae1ee60c4b349354af49b0ad1480b335299e4eb599f1421841c7b478d7f1938da2a368c5ffff2fc91e1fd658c561ccfbc57ffa6f48e4b9d9385f

    • SSDEEP

      6144:sefy8pQP0VuwLQ4sf0BDlirMDGgo5R7+s4E/wXDaCgRiFb4TUvBIBOXDAbzF:hyIQkY4s89lirMigi1N4VaCgAFbWUv6N

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

2
T1112

Tasks