General

  • Target

    1c65bdcbb08e67e90dfa55518961263c_JaffaCakes118

  • Size

    80KB

  • Sample

    240701-zaf59sxhje

  • MD5

    1c65bdcbb08e67e90dfa55518961263c

  • SHA1

    e2b5563aaaf18d8d75ed16cf1704865a4f17a35e

  • SHA256

    ca0583dcdaba9122341a45d7d0b6705d68e673ddeea4c5f36fa413b53241ea56

  • SHA512

    723031e15b1b2bd793eec03d573f448abca56b2b7ea8b1853040a47250d1751dd1e4d774e3472eb78c1958a7b2f658f81f679e899d70126cdb68c6c2e208dbfd

  • SSDEEP

    1536:pwRwO4AXSz2ALVuJtOUi4SVSnLto+ERGnfDX27DF2tnouy8q:iRw1BKTxi4K+Ecn6F2Voutq

Score
10/10

Malware Config

Targets

    • Target

      1c65bdcbb08e67e90dfa55518961263c_JaffaCakes118

    • Size

      80KB

    • MD5

      1c65bdcbb08e67e90dfa55518961263c

    • SHA1

      e2b5563aaaf18d8d75ed16cf1704865a4f17a35e

    • SHA256

      ca0583dcdaba9122341a45d7d0b6705d68e673ddeea4c5f36fa413b53241ea56

    • SHA512

      723031e15b1b2bd793eec03d573f448abca56b2b7ea8b1853040a47250d1751dd1e4d774e3472eb78c1958a7b2f658f81f679e899d70126cdb68c6c2e208dbfd

    • SSDEEP

      1536:pwRwO4AXSz2ALVuJtOUi4SVSnLto+ERGnfDX27DF2tnouy8q:iRw1BKTxi4K+Ecn6F2Voutq

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks