General
-
Target
1cfd43135212054e066d11f620a6580b_JaffaCakes118
-
Size
285KB
-
Sample
240701-3txtxa1drm
-
MD5
1cfd43135212054e066d11f620a6580b
-
SHA1
51293bb99347f01e8b52d1639a149f9a5a3de1ef
-
SHA256
e052e41a78d8ba354df0390060a6e5d23d4e0ea6e738fedb8f9df49314e2785c
-
SHA512
c53c8b122b9b8b687cc9249dd2c71546d3faf7d723590ec07bdfc3e65e6b6a1109e0043238b2829dee5ed6c836d32cf3314818be1158017fe9dcf843aede3709
-
SSDEEP
6144:Ly7gYErb/eaB78JAB7MYIQeItHMmYZCpVBr1Ee4YVkT2KedXaofzI:LQgYErb/0JAB7MYIutHMmYwHr1EenKik
Static task
static1
Behavioral task
behavioral1
Sample
1cfd43135212054e066d11f620a6580b_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1cfd43135212054e066d11f620a6580b_JaffaCakes118.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
1cfd43135212054e066d11f620a6580b_JaffaCakes118
-
Size
285KB
-
MD5
1cfd43135212054e066d11f620a6580b
-
SHA1
51293bb99347f01e8b52d1639a149f9a5a3de1ef
-
SHA256
e052e41a78d8ba354df0390060a6e5d23d4e0ea6e738fedb8f9df49314e2785c
-
SHA512
c53c8b122b9b8b687cc9249dd2c71546d3faf7d723590ec07bdfc3e65e6b6a1109e0043238b2829dee5ed6c836d32cf3314818be1158017fe9dcf843aede3709
-
SSDEEP
6144:Ly7gYErb/eaB78JAB7MYIQeItHMmYZCpVBr1Ee4YVkT2KedXaofzI:LQgYErb/0JAB7MYIutHMmYwHr1EenKik
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Deletes itself
-
Executes dropped EXE
-
Loads dropped DLL
-