General

  • Target

    16bf6b22fc080897909ad3d341d3e51c_JaffaCakes118

  • Size

    296KB

  • Sample

    240627-vbqnwazhjh

  • MD5

    16bf6b22fc080897909ad3d341d3e51c

  • SHA1

    266424c6ee18351e376848b6b1aff82e805500e1

  • SHA256

    0c9ba72f3ad469043cf9aa0f98dbaa6bf598996260dae32155ce9dc4b3bde09b

  • SHA512

    4bb5495a29edef2ccf2bfdb1ea74013d2ddb37184e8257928a5a38618f7e6826f2541312c740cf02caf4f40ff5d79e86d5a18324882e44f4b8fceea2ba76e24f

  • SSDEEP

    6144:jqVMttYRHgfCcnYbnChOdA1KY/W3dxbelOVmf/H9FoQmqZkRy0xIAzE4ym0:eVMAECqoa1y37bSHnH9WkqRIsq

Score
10/10

Malware Config

Targets

    • Target

      16bf6b22fc080897909ad3d341d3e51c_JaffaCakes118

    • Size

      296KB

    • MD5

      16bf6b22fc080897909ad3d341d3e51c

    • SHA1

      266424c6ee18351e376848b6b1aff82e805500e1

    • SHA256

      0c9ba72f3ad469043cf9aa0f98dbaa6bf598996260dae32155ce9dc4b3bde09b

    • SHA512

      4bb5495a29edef2ccf2bfdb1ea74013d2ddb37184e8257928a5a38618f7e6826f2541312c740cf02caf4f40ff5d79e86d5a18324882e44f4b8fceea2ba76e24f

    • SSDEEP

      6144:jqVMttYRHgfCcnYbnChOdA1KY/W3dxbelOVmf/H9FoQmqZkRy0xIAzE4ym0:eVMAECqoa1y37bSHnH9WkqRIsq

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks