General

  • Target

    25c023f3b929b3ea1267bc3369407c23_JaffaCakes118

  • Size

    781KB

  • Sample

    240704-wvhytasall

  • MD5

    25c023f3b929b3ea1267bc3369407c23

  • SHA1

    ccdefda67f17b302a79a5215dd0aabe24af3eaab

  • SHA256

    49508a3ffd45f5dc5ca81655f0861ae8222329a7f7bf2f58efba1f8db5980160

  • SHA512

    bdc2b0b988b9a4d41cc1a8183ee5bd912c1cb16b6f661551c5f90d1fbdb5b1343b677ba419107141bc9c6f3205dc02fe1ee72e578f77158722b0df82abedac01

  • SSDEEP

    24576:agIdOJwxcdy3IqhkU8CrO4WoSqiaEdThi0n1:pJwGyfRK4WoS5aEDi0n

Malware Config

Targets

    • Target

      25c023f3b929b3ea1267bc3369407c23_JaffaCakes118

    • Size

      781KB

    • MD5

      25c023f3b929b3ea1267bc3369407c23

    • SHA1

      ccdefda67f17b302a79a5215dd0aabe24af3eaab

    • SHA256

      49508a3ffd45f5dc5ca81655f0861ae8222329a7f7bf2f58efba1f8db5980160

    • SHA512

      bdc2b0b988b9a4d41cc1a8183ee5bd912c1cb16b6f661551c5f90d1fbdb5b1343b677ba419107141bc9c6f3205dc02fe1ee72e578f77158722b0df82abedac01

    • SSDEEP

      24576:agIdOJwxcdy3IqhkU8CrO4WoSqiaEdThi0n1:pJwGyfRK4WoS5aEDi0n

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • UAC bypass

    • ModiLoader Second Stage

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Loads dropped DLL

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

2
T1112

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

1
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

1
T1082

Tasks