General

  • Target

    1c18011c2def0325b221efc7952112f9_JaffaCakes118

  • Size

    499KB

  • Sample

    240701-xcpjbatbkb

  • MD5

    1c18011c2def0325b221efc7952112f9

  • SHA1

    c39b52f5a7c856ebd9ca3049152e03da62abee8e

  • SHA256

    771d46e06cdf01fc249bd965f721777ac5b89124d081bcc048189b3f7246e30f

  • SHA512

    092f899c8d1ab57da9a80916831f211aa746097196983dfdeb545e95c4df3b4652ad0d9845ee884a7b50a823da77ace463c2060d7e8aa8430416a67ee9254037

  • SSDEEP

    12288:RPfkp9tfoTrF3Z4mxxRSJGiz94/sCrxDVS:VuN2QmXIJG1BY

Malware Config

Targets

    • Target

      1c18011c2def0325b221efc7952112f9_JaffaCakes118

    • Size

      499KB

    • MD5

      1c18011c2def0325b221efc7952112f9

    • SHA1

      c39b52f5a7c856ebd9ca3049152e03da62abee8e

    • SHA256

      771d46e06cdf01fc249bd965f721777ac5b89124d081bcc048189b3f7246e30f

    • SHA512

      092f899c8d1ab57da9a80916831f211aa746097196983dfdeb545e95c4df3b4652ad0d9845ee884a7b50a823da77ace463c2060d7e8aa8430416a67ee9254037

    • SSDEEP

      12288:RPfkp9tfoTrF3Z4mxxRSJGiz94/sCrxDVS:VuN2QmXIJG1BY

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Server Software Component: Terminal Services DLL

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Deletes itself

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Server Software Component

1
T1505

Terminal Services DLL

1
T1505.005

Discovery

System Information Discovery

1
T1082

Tasks