Analysis
-
max time kernel
149s -
max time network
156s -
platform
windows10-2004_x64 -
resource
win10v2004-20240412-en -
resource tags
arch:x64arch:x86image:win10v2004-20240412-enlocale:en-usos:windows10-2004-x64system -
submitted
20-04-2024 19:58
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe
Resource
win7-20240221-en
windows7-x64
3 signatures
150 seconds
General
-
Target
fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe
-
Size
457KB
-
MD5
fd86ad3ec87e3e106b6305124f2f284b
-
SHA1
b3cddcd626d055bc2b0275e8ff7b30baf12128cb
-
SHA256
5670fd70ddaf5aa1d1d449b7beb1c56648a94aa73ed151729c603a458e1d461f
-
SHA512
190e4385880597fd8afd967800565247129015e5b635fe7d4577302896dcef4288e08b0f2239295ae3603488c706c2cdf84c8300351803492c2a15eb8b383a44
-
SSDEEP
6144:3cZmoZtvxiBRqGeQikLxOPYB5azK5zbPd6dV1n83iOMxMgPrlHwhZU9sI5/:3DRqG758PY/NxPwVq3iOMxXBec
Malware Config
Signatures
-
Raccoon Stealer V1 payload 4 IoCs
Processes:
resource yara_rule behavioral2/memory/2508-2-0x0000000002F80000-0x000000000300F000-memory.dmp family_raccoon_v1 behavioral2/memory/2508-3-0x0000000000400000-0x0000000002D02000-memory.dmp family_raccoon_v1 behavioral2/memory/2508-4-0x0000000000400000-0x0000000002D02000-memory.dmp family_raccoon_v1 behavioral2/memory/2508-7-0x0000000002F80000-0x000000000300F000-memory.dmp family_raccoon_v1 -
Program crash 6 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 3996 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe 2844 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe 3128 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe 2984 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe 2656 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe 1676 2508 WerFault.exe fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\fd86ad3ec87e3e106b6305124f2f284b_JaffaCakes118.exe"1⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 7482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 7842⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 8722⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 8922⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 11482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2508 -s 12282⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 2508 -ip 25081⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 2508 -ip 25081⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 536 -p 2508 -ip 25081⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 560 -p 2508 -ip 25081⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 528 -p 2508 -ip 25081⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 576 -p 2508 -ip 25081⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2508-1-0x0000000003070000-0x0000000003170000-memory.dmpFilesize
1024KB
-
memory/2508-2-0x0000000002F80000-0x000000000300F000-memory.dmpFilesize
572KB
-
memory/2508-3-0x0000000000400000-0x0000000002D02000-memory.dmpFilesize
41.0MB
-
memory/2508-4-0x0000000000400000-0x0000000002D02000-memory.dmpFilesize
41.0MB
-
memory/2508-6-0x0000000003070000-0x0000000003170000-memory.dmpFilesize
1024KB
-
memory/2508-7-0x0000000002F80000-0x000000000300F000-memory.dmpFilesize
572KB