General

  • Target

    1c8cfefaf8537dbd1a24e12fe9097f7c_JaffaCakes118

  • Size

    408KB

  • Sample

    240701-z9nz6a1ajg

  • MD5

    1c8cfefaf8537dbd1a24e12fe9097f7c

  • SHA1

    ad7b6f41eefceaec3ffb7331b4710f595c37958f

  • SHA256

    d8f1d1a1bffe081d4dbebc8c553f92adfa0c428d4d410a02d1ac4ded4ffd2525

  • SHA512

    6d36a7876df2f9cc4ce028703ed934f14fa81b3cdd0228a6bc32fb050539fff7d2132f92a2fa65721e3b3deb92d4cfcbc3eca663412b1307be0f427643f6a585

  • SSDEEP

    6144:5aDGiEqIDtTUOMYwk3LLBUOH1LtG68Wilwh1GLNIKz7I5kpBoEcWF6/9jEi++LFG:9AIOax7Lnh58WnTWp5cW45

Malware Config

Targets

    • Target

      1c8cfefaf8537dbd1a24e12fe9097f7c_JaffaCakes118

    • Size

      408KB

    • MD5

      1c8cfefaf8537dbd1a24e12fe9097f7c

    • SHA1

      ad7b6f41eefceaec3ffb7331b4710f595c37958f

    • SHA256

      d8f1d1a1bffe081d4dbebc8c553f92adfa0c428d4d410a02d1ac4ded4ffd2525

    • SHA512

      6d36a7876df2f9cc4ce028703ed934f14fa81b3cdd0228a6bc32fb050539fff7d2132f92a2fa65721e3b3deb92d4cfcbc3eca663412b1307be0f427643f6a585

    • SSDEEP

      6144:5aDGiEqIDtTUOMYwk3LLBUOH1LtG68Wilwh1GLNIKz7I5kpBoEcWF6/9jEi++LFG:9AIOax7Lnh58WnTWp5cW45

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Event Triggered Execution: Image File Execution Options Injection

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Image File Execution Options Injection

1
T1546.012

Privilege Escalation

Event Triggered Execution

1
T1546

Image File Execution Options Injection

1
T1546.012

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks