General
-
Target
197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118
-
Size
318KB
-
Sample
240628-klxvtszgrd
-
MD5
197d1cfaf6212a21eabba8a7dff2cc23
-
SHA1
968707b044e72aec108b107b75aa3f05f5f383e6
-
SHA256
035dcab3a8e6b5f616e76276e0ecbb9d6ef86f9e2459583f39c1df1557047281
-
SHA512
eb212919186bc8e42b180905ce6f3cf5d3cf31a0aa998fc56ba5259e5f1e24b2cb6f78adbb37c8dfde0ce624250c6ae9c1730180e1cfb62be41b4cdd9c78d170
-
SSDEEP
6144:KSg2/gq1hK2naL0MnICv2t5ckoFaf9c21LMluIH/pP:Lg2YqWX0iICcWJFaW2lMluIH
Behavioral task
behavioral1
Sample
197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118.exe
Resource
win10v2004-20240611-en
Malware Config
Targets
-
-
Target
197d1cfaf6212a21eabba8a7dff2cc23_JaffaCakes118
-
Size
318KB
-
MD5
197d1cfaf6212a21eabba8a7dff2cc23
-
SHA1
968707b044e72aec108b107b75aa3f05f5f383e6
-
SHA256
035dcab3a8e6b5f616e76276e0ecbb9d6ef86f9e2459583f39c1df1557047281
-
SHA512
eb212919186bc8e42b180905ce6f3cf5d3cf31a0aa998fc56ba5259e5f1e24b2cb6f78adbb37c8dfde0ce624250c6ae9c1730180e1cfb62be41b4cdd9c78d170
-
SSDEEP
6144:KSg2/gq1hK2naL0MnICv2t5ckoFaf9c21LMluIH/pP:Lg2YqWX0iICcWJFaW2lMluIH
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader First Stage
-
Loads dropped DLL
-
Adds Run key to start application
-
Drops file in System32 directory
-