General
-
Target
1750626156a832dc6f0daad03a2f6438_JaffaCakes118
-
Size
1.2MB
-
Sample
240627-ylpfcaxeqa
-
MD5
1750626156a832dc6f0daad03a2f6438
-
SHA1
97370adc8a9c1b5638b056f2c3d6bc0092e7b279
-
SHA256
784a4339e468c3cfb70d87d8dedbdc9422d2a6e272eced72acb51317ec78d215
-
SHA512
ab3a8560564f4d413cf9df6a1b71a819b1a878c33db7127ffe3c1563a1f54b8735eaf6f20a2d87190d5d94bd5cb018b9e7dbbfdab92d308ed0fabebad5875d36
-
SSDEEP
24576:isQeDBpxbGXuSmW055ZuPEd36vpvN53erExKUjzMAIEAJnf:iteL48WWdC4SjNaf
Behavioral task
behavioral1
Sample
1750626156a832dc6f0daad03a2f6438_JaffaCakes118.exe
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
1750626156a832dc6f0daad03a2f6438_JaffaCakes118.exe
Resource
win10v2004-20240226-en
Malware Config
Targets
-
-
Target
1750626156a832dc6f0daad03a2f6438_JaffaCakes118
-
Size
1.2MB
-
MD5
1750626156a832dc6f0daad03a2f6438
-
SHA1
97370adc8a9c1b5638b056f2c3d6bc0092e7b279
-
SHA256
784a4339e468c3cfb70d87d8dedbdc9422d2a6e272eced72acb51317ec78d215
-
SHA512
ab3a8560564f4d413cf9df6a1b71a819b1a878c33db7127ffe3c1563a1f54b8735eaf6f20a2d87190d5d94bd5cb018b9e7dbbfdab92d308ed0fabebad5875d36
-
SSDEEP
24576:isQeDBpxbGXuSmW055ZuPEd36vpvN53erExKUjzMAIEAJnf:iteL48WWdC4SjNaf
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader First Stage
-
Executes dropped EXE
-
Enumerates connected drives
Attempts to read the root path of hard drives other than the default C: drive.
-
Drops file in System32 directory
-