General
-
Target
1b4fc42cbb32187b36c32f69276a9a43_JaffaCakes118
-
Size
154KB
-
Sample
240701-pp7xesvfnl
-
MD5
1b4fc42cbb32187b36c32f69276a9a43
-
SHA1
c02ba2c8080f967262baa4f06dcce7878b655e23
-
SHA256
4c2ca2e13a3b2ae9c5a55f5c1d2c68bbd6c5834361c735c23e02e365ee81b14f
-
SHA512
afae33594e1f45fffa961bd7119f335c904c9621aa2e64c25316a5db2dfd2adf731249ff111d9bf3ea0cedb51dee9f38b90f10d03e11367ce86bf8a0fb26e756
-
SSDEEP
3072:vl+8bQ/Ry/FtVttsFm4qMHbadBJvC0iTFF:48k/G3VAnHbSC/
Behavioral task
behavioral1
Sample
1b4fc42cbb32187b36c32f69276a9a43_JaffaCakes118.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
1b4fc42cbb32187b36c32f69276a9a43_JaffaCakes118.exe
Resource
win10v2004-20240611-en
Malware Config
Targets
-
-
Target
1b4fc42cbb32187b36c32f69276a9a43_JaffaCakes118
-
Size
154KB
-
MD5
1b4fc42cbb32187b36c32f69276a9a43
-
SHA1
c02ba2c8080f967262baa4f06dcce7878b655e23
-
SHA256
4c2ca2e13a3b2ae9c5a55f5c1d2c68bbd6c5834361c735c23e02e365ee81b14f
-
SHA512
afae33594e1f45fffa961bd7119f335c904c9621aa2e64c25316a5db2dfd2adf731249ff111d9bf3ea0cedb51dee9f38b90f10d03e11367ce86bf8a0fb26e756
-
SSDEEP
3072:vl+8bQ/Ry/FtVttsFm4qMHbadBJvC0iTFF:48k/G3VAnHbSC/
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-