General

  • Target

    25f7a060beeec7a5b952788465db3e8c_JaffaCakes118

  • Size

    1.6MB

  • Sample

    240704-x28ngsvbnp

  • MD5

    25f7a060beeec7a5b952788465db3e8c

  • SHA1

    616cb6087c9c11107a82d1cdd6d403c3c9cffd18

  • SHA256

    08e2899d799d4b103ce73143d8d0cac5803d5a9bd8d75d35624de0a5278df15d

  • SHA512

    af9d8834e181cd14a44f4a109d9036fa6d70953e0c987a478634c632783d1b63888116c846d3d25f9b087e7ea45a4ee3ecd5d69686a55bd630c85b3c00379301

  • SSDEEP

    49152:0wmG94hUbREXnDKK7XxIx9P0FUhA6lpUKw:XFYUbeXnGK7X0TZw

Malware Config

Targets

    • Target

      25f7a060beeec7a5b952788465db3e8c_JaffaCakes118

    • Size

      1.6MB

    • MD5

      25f7a060beeec7a5b952788465db3e8c

    • SHA1

      616cb6087c9c11107a82d1cdd6d403c3c9cffd18

    • SHA256

      08e2899d799d4b103ce73143d8d0cac5803d5a9bd8d75d35624de0a5278df15d

    • SHA512

      af9d8834e181cd14a44f4a109d9036fa6d70953e0c987a478634c632783d1b63888116c846d3d25f9b087e7ea45a4ee3ecd5d69686a55bd630c85b3c00379301

    • SSDEEP

      49152:0wmG94hUbREXnDKK7XxIx9P0FUhA6lpUKw:XFYUbeXnGK7X0TZw

    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • UAC bypass

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Adds Run key to start application

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

3
T1112

Discovery

System Information Discovery

2
T1082

Tasks