General

  • Target

    1bbce924d9b761a165bff0df9afa458c_JaffaCakes118

  • Size

    649KB

  • Sample

    240701-sbwtsaxemb

  • MD5

    1bbce924d9b761a165bff0df9afa458c

  • SHA1

    473bd5e80674cdbfbea6cea4d5b5b392f8aa52af

  • SHA256

    be05462d54258875d49c2cae5c9c5267ccc9c1471e255e9d981b246d2c0e95d1

  • SHA512

    fe8890c7eed45db8a0fd70e55481eee184dd90199701c0f547439862abf21a16a4c822658fedddf62851545a5b91ddf012c46ea3c408df080a553f205df8c7e5

  • SSDEEP

    12288:Dzq4uVpY4TSipHDdpV9NT5cQEOxylLXUD7lyyLzdmf5OZ7Zy:3qJpxHNTORWyEHlyyfdU

Malware Config

Targets

    • Target

      1bbce924d9b761a165bff0df9afa458c_JaffaCakes118

    • Size

      649KB

    • MD5

      1bbce924d9b761a165bff0df9afa458c

    • SHA1

      473bd5e80674cdbfbea6cea4d5b5b392f8aa52af

    • SHA256

      be05462d54258875d49c2cae5c9c5267ccc9c1471e255e9d981b246d2c0e95d1

    • SHA512

      fe8890c7eed45db8a0fd70e55481eee184dd90199701c0f547439862abf21a16a4c822658fedddf62851545a5b91ddf012c46ea3c408df080a553f205df8c7e5

    • SSDEEP

      12288:Dzq4uVpY4TSipHDdpV9NT5cQEOxylLXUD7lyyLzdmf5OZ7Zy:3qJpxHNTORWyEHlyyfdU

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • ASPack v2.12-2.42

      Detects executables packed with ASPack v2.12-2.42

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks