General

  • Target

    18f54f3a1cf7e60b35662cce35f84126_JaffaCakes118

  • Size

    688KB

  • Sample

    240628-f8rvwatdqd

  • MD5

    18f54f3a1cf7e60b35662cce35f84126

  • SHA1

    539024d5ccc955038f7cf75b8c96ad62cacf31d3

  • SHA256

    5be3ee0c15bbbbf36f888c7b59ab271801de4569bf8875872399f3305a781def

  • SHA512

    b35e9088ee245d39cbabef08375180fc43ae4a381f766b4b7b87982a061ff408c744b0892a32dbcaf37f7863c293fb4988644a98af24535e6b126f4e24d4d103

  • SSDEEP

    12288:T8LLywMdqOnAuvBWF/2LtjVK4LqCF3Z4mxx6awUQ55JIqsvR33NeiH:4LcqOnlvgFI+4L9QmX6awD5/xsvNNeS

Score
10/10

Malware Config

Targets

    • Target

      18f54f3a1cf7e60b35662cce35f84126_JaffaCakes118

    • Size

      688KB

    • MD5

      18f54f3a1cf7e60b35662cce35f84126

    • SHA1

      539024d5ccc955038f7cf75b8c96ad62cacf31d3

    • SHA256

      5be3ee0c15bbbbf36f888c7b59ab271801de4569bf8875872399f3305a781def

    • SHA512

      b35e9088ee245d39cbabef08375180fc43ae4a381f766b4b7b87982a061ff408c744b0892a32dbcaf37f7863c293fb4988644a98af24535e6b126f4e24d4d103

    • SSDEEP

      12288:T8LLywMdqOnAuvBWF/2LtjVK4LqCF3Z4mxx6awUQ55JIqsvR33NeiH:4LcqOnlvgFI+4L9QmX6awD5/xsvNNeS

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks