logo

Warning Against ModiLoader (DBatLoader) Spreading via MS Windows CAB Header Batch File (*.cmd)

ID: 474ba7aa-9a7b-50b5-8023-2fb182ac9b43

STIX ID: report--474ba7aa-9a7b-50b5-8023-2fb182ac9b43

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-01-13

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC observed a December 2024 campaign delivering ModiLoader (DBatLoader) via PO-themed emails that attach .cmd files crafted with a CAB (MSCF) header (and a PNG prefix) to bypass filters; the .cmd acts as a CAB-type loader that uses extrac32 to extract an EXE into %temp% and run it. The report documents the binary structure, execution flow, images of the artifacts, and provides two MD5 IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.