General

  • Target

    ffc57d84cdd184d90966b6d0bfd925c3_JaffaCakes118

  • Size

    577KB

  • MD5

    ffc57d84cdd184d90966b6d0bfd925c3

  • SHA1

    f280979956162f01c8119328df78ce64247ff3da

  • SHA256

    b8fecafb0ea8ed59d3c66ea34f14f25f1354589750fc854ff78c11e10cc3421b

  • SHA512

    550fa6203cb4ef67bea0140681626ba5589f3d5f0a30dc46a7bcd9b4acb0cbef8987b16aeacd8589916418abbd8f229433efed624cda5a4633fe8491a0663676

  • SSDEEP

    12288:XZRR5hRueKeuUMd1oBPIEQq+ePa9Xtz+vTV8+7gSPRqJwA5:X7rKmMsBPINXYTVP7giI++

Score
3/10

Malware Config

Signatures

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • ffc57d84cdd184d90966b6d0bfd925c3_JaffaCakes118
    .eml
    • https://www.grid-ess.com/

    • https://crm.xiaoman.cn/pro/mail/www.bullsbattery.com

    • https://crm.xiaoman.cn/pro/mail/www.lithium-battery-factory.com

    • https://crm.xiaoman.cn/pro/mail/www.lithiumforkliftbattery.com/

  • Transfer Swift Copy.zip
    .zip
  • Transfer Swift Copy.exe
    .exe windows:6 windows x86 arch:x86

    97750a00050e37c7b56da7bc3864f0f1


    Headers

    Imports

    Sections

  • email-html-2.txt
    .html
  • email-plain-1.txt
  • image.png
    .png