General
-
Target
13903a7e289cc092e67b748dfea5389c.bin
-
Size
489KB
-
Sample
240628-btxelawdkr
-
MD5
13903a7e289cc092e67b748dfea5389c
-
SHA1
5c4c944e6bc42212165379ce8fa707672a5be10d
-
SHA256
26f2439cf56b5fd64aa2b22519e33aff692bb9af18a24bc3ba1f450840d7a476
-
SHA512
f0f74ef891ca08800b58e1e311cbe30be669ce24510c08509380392e2eaa7a3216a1ffeac61c50a5e89211efe546d6fbe368139deb8dfa26e9bc54473c9783f3
-
SSDEEP
12288:SRyk2lzMdfiZRMGs+S2AjS8ocJxmH5I0I:myk2lzGiQMc98ZIh
Static task
static1
Behavioral task
behavioral1
Sample
13903a7e289cc092e67b748dfea5389c.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
13903a7e289cc092e67b748dfea5389c.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
13903a7e289cc092e67b748dfea5389c.bin
-
Size
489KB
-
MD5
13903a7e289cc092e67b748dfea5389c
-
SHA1
5c4c944e6bc42212165379ce8fa707672a5be10d
-
SHA256
26f2439cf56b5fd64aa2b22519e33aff692bb9af18a24bc3ba1f450840d7a476
-
SHA512
f0f74ef891ca08800b58e1e311cbe30be669ce24510c08509380392e2eaa7a3216a1ffeac61c50a5e89211efe546d6fbe368139deb8dfa26e9bc54473c9783f3
-
SSDEEP
12288:SRyk2lzMdfiZRMGs+S2AjS8ocJxmH5I0I:myk2lzGiQMc98ZIh
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Deletes itself
-
Executes dropped EXE
-
Loads dropped DLL
-
Drops file in System32 directory
-
Suspicious use of SetThreadContext
-