General
-
Target
1e9b10cd5be0d0387743b2c78f48f92a_JaffaCakes118
-
Size
707KB
-
Sample
240702-j6rnwaxeqr
-
MD5
1e9b10cd5be0d0387743b2c78f48f92a
-
SHA1
b639cd1cb6e2e2bc7ea03d948090616d0cdefaff
-
SHA256
ed0a2b2d3c2b26fc8d92f6aeed3fffe76079ffd75efe6879c8ee1310293eba71
-
SHA512
8445f0d00bc7389c4562b63770efce15496f0fbb9be99600e8ab01f0012144e81ba4111f778732ea5581eb25cdd303652a0d055a59ff26939dd60ce3757474c4
-
SSDEEP
12288:bsWdVgX1MwKcjZ+fEEIjEOyk/AXqUpQrX2Y5f4J0EsvTJRI:Dzg6wKcV+sECkXGrm4yAvTI
Behavioral task
behavioral1
Sample
1e9b10cd5be0d0387743b2c78f48f92a_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1e9b10cd5be0d0387743b2c78f48f92a_JaffaCakes118.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
1e9b10cd5be0d0387743b2c78f48f92a_JaffaCakes118
-
Size
707KB
-
MD5
1e9b10cd5be0d0387743b2c78f48f92a
-
SHA1
b639cd1cb6e2e2bc7ea03d948090616d0cdefaff
-
SHA256
ed0a2b2d3c2b26fc8d92f6aeed3fffe76079ffd75efe6879c8ee1310293eba71
-
SHA512
8445f0d00bc7389c4562b63770efce15496f0fbb9be99600e8ab01f0012144e81ba4111f778732ea5581eb25cdd303652a0d055a59ff26939dd60ce3757474c4
-
SSDEEP
12288:bsWdVgX1MwKcjZ+fEEIjEOyk/AXqUpQrX2Y5f4J0EsvTJRI:Dzg6wKcV+sECkXGrm4yAvTI
Score10/10-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage
-
Deletes itself
-
Executes dropped EXE
-
Loads dropped DLL
-