General

  • Target

    eee062f43b42bba39663fb628a7da063_JaffaCakes118

  • Size

    66KB

  • MD5

    eee062f43b42bba39663fb628a7da063

  • SHA1

    c349ca54ffcd54077f1215740029f909c85ccc06

  • SHA256

    abed6d2ad917018dbd98efabc31bde51ff3cc2e4f71b60e7b8a71344a90df0d7

  • SHA512

    19fad524b904eea8fa31f8c4cf2cda03d58e2a7e10a476896f53799b66d10291420c7ad997ffe8d829f32dcc07695b0e68dfd8f9fa8785ebc821d237b58ca12e

  • SSDEEP

    1536:Rq8PQsGtzp/dsSTnOuhBRMRSuAM4yxSZ9:RqZsGP/awZhBRKH

Score
10/10

Malware Config

Extracted

Family

bazarloader

C2

164.90.198.79

164.90.198.77

blackrain15.bazar

bluehail.bazar

Signatures

  • Bazar/Team9 Loader payload 1 IoCs
  • Bazarloader family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • eee062f43b42bba39663fb628a7da063_JaffaCakes118
    .dll regsvr32 windows:6 windows x64 arch:x64

    2a663bf3afdb2ff4d5e5198c54863af2


    Headers

    Imports

    Exports

    Sections