General

  • Target

    16e3a183e85d12f233f94a0eec7072c5_JaffaCakes118

  • Size

    1.1MB

  • Sample

    240627-v6gdpavajq

  • MD5

    16e3a183e85d12f233f94a0eec7072c5

  • SHA1

    0fb06c1d9fcb4ab06141de860733324f1f8bc4b2

  • SHA256

    64d9c4dfb303ddce01dc2953b451559ca8e2e3036bdc99fc26efb2c45e052f08

  • SHA512

    fdfcd8ac47eab7a4d80f843b9e9d6e89af8997f8eaa8623b6f102462738b8faa7368542c69d7800f9c9301804c2d57315874fc382f864e7adb4336571407fde3

  • SSDEEP

    24576:TcCrn42vGV4rb/n5c5EdJzv9yWT7LkC4EuQnECjbQKGQ3g5N:TcCI+zdJzlfT7LkCyQECjbrY

Score
10/10

Malware Config

Targets

    • Target

      16e3a183e85d12f233f94a0eec7072c5_JaffaCakes118

    • Size

      1.1MB

    • MD5

      16e3a183e85d12f233f94a0eec7072c5

    • SHA1

      0fb06c1d9fcb4ab06141de860733324f1f8bc4b2

    • SHA256

      64d9c4dfb303ddce01dc2953b451559ca8e2e3036bdc99fc26efb2c45e052f08

    • SHA512

      fdfcd8ac47eab7a4d80f843b9e9d6e89af8997f8eaa8623b6f102462738b8faa7368542c69d7800f9c9301804c2d57315874fc382f864e7adb4336571407fde3

    • SSDEEP

      24576:TcCrn42vGV4rb/n5c5EdJzv9yWT7LkC4EuQnECjbQKGQ3g5N:TcCI+zdJzlfT7LkCyQECjbrY

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Tasks