General

  • Target

    1984d51fc9e907b5bc3444228be8fd9b_JaffaCakes118

  • Size

    537KB

  • Sample

    240628-ksrbmatdpq

  • MD5

    1984d51fc9e907b5bc3444228be8fd9b

  • SHA1

    6ed4e9121b69937e32243a57c1934627428e2911

  • SHA256

    5ca1e75eb315b5fe9f409aee44a1344bbdee673b0e7cbaffac33ace12c1ffb5e

  • SHA512

    d313782c22eedeb595aaed37dfdeb68fc3d2bfe99f6c4e6c0836e80d5330a7cc89cc663ebd5ea6af65f63b87fc42526cccb673d4e35ee191d5cebeec54350571

  • SSDEEP

    12288:31GlRzSEY5cxxGjcmLKO9F3Z4mxxgv5bSRZsD8:3ORdEcecmR9QmXVoD8

Score
10/10

Malware Config

Targets

    • Target

      1984d51fc9e907b5bc3444228be8fd9b_JaffaCakes118

    • Size

      537KB

    • MD5

      1984d51fc9e907b5bc3444228be8fd9b

    • SHA1

      6ed4e9121b69937e32243a57c1934627428e2911

    • SHA256

      5ca1e75eb315b5fe9f409aee44a1344bbdee673b0e7cbaffac33ace12c1ffb5e

    • SHA512

      d313782c22eedeb595aaed37dfdeb68fc3d2bfe99f6c4e6c0836e80d5330a7cc89cc663ebd5ea6af65f63b87fc42526cccb673d4e35ee191d5cebeec54350571

    • SSDEEP

      12288:31GlRzSEY5cxxGjcmLKO9F3Z4mxxgv5bSRZsD8:3ORdEcecmR9QmXVoD8

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks