General

  • Target

    1a1d4d5e7b700805a09396477a7e45b5_JaffaCakes118

  • Size

    730KB

  • Sample

    240628-pm674szamc

  • MD5

    1a1d4d5e7b700805a09396477a7e45b5

  • SHA1

    759002b0ca62d0ee60bbc97a9525461129d406a4

  • SHA256

    05e4024a3412bd356c58593fdb11335c5bfa8d49660fa587ce73e7044dffd70a

  • SHA512

    daffdc20b3cee52395df82901f29b133c63a4a7a2225dbd2648d92db95f030287d07865dc967f02671e2780ac23858049a645fe011c982d800279d0e9052d116

  • SSDEEP

    12288:FAf+F+JynQWf9V0KVPmUD56YNZJxzqznJddCUWlEpE5bmVL:FAhJWQWQKVPH6YrzMmlEpSbmZ

Score
10/10

Malware Config

Targets

    • Target

      1a1d4d5e7b700805a09396477a7e45b5_JaffaCakes118

    • Size

      730KB

    • MD5

      1a1d4d5e7b700805a09396477a7e45b5

    • SHA1

      759002b0ca62d0ee60bbc97a9525461129d406a4

    • SHA256

      05e4024a3412bd356c58593fdb11335c5bfa8d49660fa587ce73e7044dffd70a

    • SHA512

      daffdc20b3cee52395df82901f29b133c63a4a7a2225dbd2648d92db95f030287d07865dc967f02671e2780ac23858049a645fe011c982d800279d0e9052d116

    • SSDEEP

      12288:FAf+F+JynQWf9V0KVPmUD56YNZJxzqznJddCUWlEpE5bmVL:FAhJWQWQKVPH6YrzMmlEpSbmZ

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Executes dropped EXE

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks