General
-
Target
16c380619fd3eb7b5b1d5934519d2b9e_JaffaCakes118
-
Size
376KB
-
Sample
240627-vereks1ald
-
MD5
16c380619fd3eb7b5b1d5934519d2b9e
-
SHA1
c1e33621fd38d8fa97ecefda044a1219d4f27074
-
SHA256
4dca5984c0298638d7bd4cdd20f9dbbc8700258aabea04474a16d680ae74a916
-
SHA512
b94053382ae6af0ca72eace148a358bbe4a6338a6bfef0a1a92f10135b5d8376ceb277c39f613b450fa9c880b547c27856bcb23d90d5dc290f0bb209bff67b14
-
SSDEEP
6144:iNasmPwXquO1fSRg6EijYTDfUUupAw7U6HDXy1LJPXfimueN9cNbITQ+MCr0:iNj6PSO5C75DCd5zue/cNbIT4l
Static task
static1
Behavioral task
behavioral1
Sample
16c380619fd3eb7b5b1d5934519d2b9e_JaffaCakes118.exe
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
16c380619fd3eb7b5b1d5934519d2b9e_JaffaCakes118.exe
Resource
win10v2004-20240226-en
Malware Config
Targets
-
-
Target
16c380619fd3eb7b5b1d5934519d2b9e_JaffaCakes118
-
Size
376KB
-
MD5
16c380619fd3eb7b5b1d5934519d2b9e
-
SHA1
c1e33621fd38d8fa97ecefda044a1219d4f27074
-
SHA256
4dca5984c0298638d7bd4cdd20f9dbbc8700258aabea04474a16d680ae74a916
-
SHA512
b94053382ae6af0ca72eace148a358bbe4a6338a6bfef0a1a92f10135b5d8376ceb277c39f613b450fa9c880b547c27856bcb23d90d5dc290f0bb209bff67b14
-
SSDEEP
6144:iNasmPwXquO1fSRg6EijYTDfUUupAw7U6HDXy1LJPXfimueN9cNbITQ+MCr0:iNj6PSO5C75DCd5zue/cNbIT4l
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Deletes itself
-
Executes dropped EXE
-
Loads dropped DLL
-
Drops file in System32 directory
-