General

  • Target

    269d98d6d42b52375626fde61db67281_JaffaCakes118

  • Size

    320KB

  • Sample

    240704-3dphlaxfph

  • MD5

    269d98d6d42b52375626fde61db67281

  • SHA1

    d972078d8bfcadfd3ccb2e494c58d65035d341eb

  • SHA256

    de46075e7db5cd35c194ef352bcfacd63541ef87e26ac475ee571d6ec2490637

  • SHA512

    2780fe3814ee974c2cd99906d52a48c8a67cc68ab0934c1d91fcec148d1fe49bdb23eb5f630a1a02cc02c34deae1a9b352fc6f2107ac74650f007b043f402a92

  • SSDEEP

    6144:Zi0F1cBEtu/lzj/GS59IUw2IIGkrvdaAD9YDXCh6YCHV2uH2YPFu+Mf:PFwNzj/GSA65xYD52u3g+a

Score
10/10

Malware Config

Targets

    • Target

      269d98d6d42b52375626fde61db67281_JaffaCakes118

    • Size

      320KB

    • MD5

      269d98d6d42b52375626fde61db67281

    • SHA1

      d972078d8bfcadfd3ccb2e494c58d65035d341eb

    • SHA256

      de46075e7db5cd35c194ef352bcfacd63541ef87e26ac475ee571d6ec2490637

    • SHA512

      2780fe3814ee974c2cd99906d52a48c8a67cc68ab0934c1d91fcec148d1fe49bdb23eb5f630a1a02cc02c34deae1a9b352fc6f2107ac74650f007b043f402a92

    • SSDEEP

      6144:Zi0F1cBEtu/lzj/GS59IUw2IIGkrvdaAD9YDXCh6YCHV2uH2YPFu+Mf:PFwNzj/GSA65xYD52u3g+a

    Score
    10/10
    • ModiLoader, DBatLoader

      ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

    • ModiLoader Second Stage

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Tasks