General

  • Target

    16f23bda566de7efec3238b427d33946_JaffaCakes118

  • Size

    306KB

  • Sample

    240627-whcahavemr

  • MD5

    16f23bda566de7efec3238b427d33946

  • SHA1

    f45fc8eb72c789126c7b1f95ed506d3033038673

  • SHA256

    31a7d14320d4b3e8d00af7bc2f88d97a60b1e742ddc2820ad616650a752e7deb

  • SHA512

    f30cab2254c9b8693a5c53bcc1eb87d358b873d6c445f5b0062a9045148a1d446730332ae89152ab475f01c1aa35d64300295b1ad0485943634da15edd0ee13a

  • SSDEEP

    6144:jXUT+DSra6MwqyKKOlLBd3wCl2M19JSMbyYwZQvDkw2Q2EFsRk7kd0:jXi6wqyKxdLACl2a9MMmYwZgr2Q2Eg6

Score
10/10

Malware Config

Targets

    • Target

      16f23bda566de7efec3238b427d33946_JaffaCakes118

    • Size

      306KB

    • MD5

      16f23bda566de7efec3238b427d33946

    • SHA1

      f45fc8eb72c789126c7b1f95ed506d3033038673

    • SHA256

      31a7d14320d4b3e8d00af7bc2f88d97a60b1e742ddc2820ad616650a752e7deb

    • SHA512

      f30cab2254c9b8693a5c53bcc1eb87d358b873d6c445f5b0062a9045148a1d446730332ae89152ab475f01c1aa35d64300295b1ad0485943634da15edd0ee13a

    • SSDEEP

      6144:jXUT+DSra6MwqyKKOlLBd3wCl2M19JSMbyYwZQvDkw2Q2EFsRk7kd0:jXi6wqyKxdLACl2a9MMmYwZgr2Q2Eg6

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks