General
-
Target
19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118
-
Size
181KB
-
Sample
240628-lfk5hsvemp
-
MD5
19a049119999ce6179a6f2c7f1bc2cc3
-
SHA1
9d69bfb8c0522f626dac62a2642b6488af30da41
-
SHA256
90260fb517aef90268e0f95a4cfef939887f5acbd9448b2a291a93e65d13c1cb
-
SHA512
8d6e9e2026ec4f57f16dee83ab2b0cdeb7cf4c5acc8e1c1a17824555c0855dc16313f79ef0887f341d13df664978baa06d7f96fe087b5ea5c668431d12244de0
-
SSDEEP
3072:bLH3Qp/pHocucy4+qpbHiNeC2uEtcBVdI243cG1plubZCpg9CEP9o2ullx5cK5w:v6IcwTqpbiNeC3I/m8oCEyZlaKy
Static task
static1
Behavioral task
behavioral1
Sample
19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118.exe
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
19a049119999ce6179a6f2c7f1bc2cc3_JaffaCakes118
-
Size
181KB
-
MD5
19a049119999ce6179a6f2c7f1bc2cc3
-
SHA1
9d69bfb8c0522f626dac62a2642b6488af30da41
-
SHA256
90260fb517aef90268e0f95a4cfef939887f5acbd9448b2a291a93e65d13c1cb
-
SHA512
8d6e9e2026ec4f57f16dee83ab2b0cdeb7cf4c5acc8e1c1a17824555c0855dc16313f79ef0887f341d13df664978baa06d7f96fe087b5ea5c668431d12244de0
-
SSDEEP
3072:bLH3Qp/pHocucy4+qpbHiNeC2uEtcBVdI243cG1plubZCpg9CEP9o2ullx5cK5w:v6IcwTqpbiNeC3I/m8oCEyZlaKy
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
Modifies visiblity of hidden/system files in Explorer
-
ModiLoader Second Stage
-
Drops file in Drivers directory
-
Deletes itself
-
Loads dropped DLL
-
Modifies WinLogon
-