General
-
Target
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118
-
Size
244KB
-
Sample
240701-vey5esygnf
-
MD5
1bc5c9316e96c1e084c637324adb5ab4
-
SHA1
5b0e20005021e8535463eb368114f7fe8dd09733
-
SHA256
4d5103192e78425daa38b2bf589d44d22a1081d8993af9d8830d15b686a508f3
-
SHA512
27e09570a1f7cb8eb6da61264de59f584befc10616151fddaf32d431a8c02e716a98bf137f32a6ab72d19b2363e7e14e8c2a5caaa1b67c75fb769c3c14b121a4
-
SSDEEP
6144:VtDO5bDO5XZXxS97mkWJ9HGeF2V+YXxH1MitwfV1Q:a525pXqSkWJBJTIHufVC
Static task
static1
Behavioral task
behavioral1
Sample
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118.exe
Resource
win10v2004-20240611-en
Malware Config
Targets
-
-
Target
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118
-
Size
244KB
-
MD5
1bc5c9316e96c1e084c637324adb5ab4
-
SHA1
5b0e20005021e8535463eb368114f7fe8dd09733
-
SHA256
4d5103192e78425daa38b2bf589d44d22a1081d8993af9d8830d15b686a508f3
-
SHA512
27e09570a1f7cb8eb6da61264de59f584befc10616151fddaf32d431a8c02e716a98bf137f32a6ab72d19b2363e7e14e8c2a5caaa1b67c75fb769c3c14b121a4
-
SSDEEP
6144:VtDO5bDO5XZXxS97mkWJ9HGeF2V+YXxH1MitwfV1Q:a525pXqSkWJBJTIHufVC
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Suspicious use of SetThreadContext
-