General

  • Target

    1c7f50c5e44313e78f6bc2e18de2f4c6_JaffaCakes118

  • Size

    38KB

  • Sample

    240701-zxsgtazbrd

  • MD5

    1c7f50c5e44313e78f6bc2e18de2f4c6

  • SHA1

    cd2f34c415b92f1a928f27beb392f54ee617da88

  • SHA256

    26ab6e684b0b3f307be582bf135619ba278bc92c15dc1bf236ee21fdc82e25a8

  • SHA512

    3bf6d41a26b4a675bbeb10d4d8a5971fbc4028714585e921f63ebd40226901e4d1ebefd66c57bcbcdf62d7008ff44a1dcbb6fddce1d562743bf97190e9b7475c

  • SSDEEP

    768:eBycquQyb2sZvFUK0aMczvPlMn0K9HXML4Q/Kbe7mh3:7cquQGdU6Mczu0KHXtAmB

Malware Config

Targets

    • Target

      1c7f50c5e44313e78f6bc2e18de2f4c6_JaffaCakes118

    • Size

      38KB

    • MD5

      1c7f50c5e44313e78f6bc2e18de2f4c6

    • SHA1

      cd2f34c415b92f1a928f27beb392f54ee617da88

    • SHA256

      26ab6e684b0b3f307be582bf135619ba278bc92c15dc1bf236ee21fdc82e25a8

    • SHA512

      3bf6d41a26b4a675bbeb10d4d8a5971fbc4028714585e921f63ebd40226901e4d1ebefd66c57bcbcdf62d7008ff44a1dcbb6fddce1d562743bf97190e9b7475c

    • SSDEEP

      768:eBycquQyb2sZvFUK0aMczvPlMn0K9HXML4Q/Kbe7mh3:7cquQGdU6Mczu0KHXtAmB

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks