General

  • Target

    1e444823916a8d7d0dd38d00a44f760a_JaffaCakes118

  • Size

    1.1MB

  • Sample

    240702-gydqyatcnj

  • MD5

    1e444823916a8d7d0dd38d00a44f760a

  • SHA1

    97d266ce30d4056a9965aeef57fc4b5c721fee17

  • SHA256

    3abda37937391978ee17ac2e8ee92cb2beea480b5b946f938cb0db0be315d631

  • SHA512

    0adf8185893996b48acbb92be66236df3b1d5ec6db162317011e02803a3e4e43a4e46a5a630b9369604055008b3dcb1913cc599ebdb52226e0fab4afe5934eb3

  • SSDEEP

    24576:gXLtyHjeZbKX7RYR0ASUIXG2VowHDnHiTCDCCIurGEQLHwom:g7tyHkKrRu0LUI22ZrCTCeNuH6HTm

Malware Config

Targets

    • Target

      1e444823916a8d7d0dd38d00a44f760a_JaffaCakes118

    • Size

      1.1MB

    • MD5

      1e444823916a8d7d0dd38d00a44f760a

    • SHA1

      97d266ce30d4056a9965aeef57fc4b5c721fee17

    • SHA256

      3abda37937391978ee17ac2e8ee92cb2beea480b5b946f938cb0db0be315d631

    • SHA512

      0adf8185893996b48acbb92be66236df3b1d5ec6db162317011e02803a3e4e43a4e46a5a630b9369604055008b3dcb1913cc599ebdb52226e0fab4afe5934eb3

    • SSDEEP

      24576:gXLtyHjeZbKX7RYR0ASUIXG2VowHDnHiTCDCCIurGEQLHwom:g7tyHkKrRu0LUI22ZrCTCeNuH6HTm

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • Modifies WinLogon for persistence

    • ModiLoader Second Stage

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks