Analysis
-
max time kernel
140s -
max time network
164s -
platform
windows10-2004_x64 -
resource
win10v2004-20240226-en -
resource tags
arch:x64arch:x86image:win10v2004-20240226-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 19:52
Static task
static1
Behavioral task
behavioral1
Sample
1c4bd26b132f2493135a476f25e40666_JaffaCakes118.dll
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
1c4bd26b132f2493135a476f25e40666_JaffaCakes118.dll
Resource
win10v2004-20240226-en
General
-
Target
1c4bd26b132f2493135a476f25e40666_JaffaCakes118.dll
-
Size
25KB
-
MD5
1c4bd26b132f2493135a476f25e40666
-
SHA1
f921e8acf07850e4e4cd19ba090d728e11580e5d
-
SHA256
7af22867dc1cfd89eb98d4c9c2553653a583efba58753440d875436b3ab7c58c
-
SHA512
f64504cc9a5acdd14b98178bcf6812e928e74290ac87969fce4c6facf9132efff6b80a0e277fea14c5d7335bfd4e0f335fdbdf60601bde6fab91b289ff981342
-
SSDEEP
768:bk258X47a6H3LLzKav6rD9aeU+CairBh:bk258o7dHbLzKavyazuE
Malware Config
Signatures
-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage 2 IoCs
Processes:
resource yara_rule behavioral2/memory/1280-1-0x0000000000400000-0x000000000041F000-memory.dmp modiloader_stage2 behavioral2/memory/1280-3-0x0000000000400000-0x000000000041F000-memory.dmp modiloader_stage2 -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
regsvr32.exedescription pid process target process PID 2636 wrote to memory of 1280 2636 regsvr32.exe regsvr32.exe PID 2636 wrote to memory of 1280 2636 regsvr32.exe regsvr32.exe PID 2636 wrote to memory of 1280 2636 regsvr32.exe regsvr32.exe
Processes
-
C:\Windows\system32\regsvr32.exeregsvr32 /s C:\Users\Admin\AppData\Local\Temp\1c4bd26b132f2493135a476f25e40666_JaffaCakes118.dll1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\regsvr32.exe/s C:\Users\Admin\AppData\Local\Temp\1c4bd26b132f2493135a476f25e40666_JaffaCakes118.dll2⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=3708 --field-trial-handle=1928,i,13242902252791919845,10377620236057253993,262144 --variations-seed-version /prefetch:81⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/1280-0-0x0000000000400000-0x000000000041F000-memory.dmpFilesize
124KB
-
memory/1280-1-0x0000000000400000-0x000000000041F000-memory.dmpFilesize
124KB
-
memory/1280-2-0x0000000000417000-0x0000000000418000-memory.dmpFilesize
4KB
-
memory/1280-3-0x0000000000400000-0x000000000041F000-memory.dmpFilesize
124KB