Analysis
-
max time kernel
149s -
max time network
150s -
platform
windows7_x64 -
resource
win7-20231129-en -
resource tags
arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system -
submitted
05-05-2024 22:44
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
198895bd9f49e2dc78c0f82420bb6f87_JaffaCakes118.dll
Resource
win7-20231129-en
4 signatures
150 seconds
General
-
Target
198895bd9f49e2dc78c0f82420bb6f87_JaffaCakes118.dll
-
Size
211KB
-
MD5
198895bd9f49e2dc78c0f82420bb6f87
-
SHA1
f6c2077832d52f082631fe8e3efabef6c329a8a0
-
SHA256
a95efda438fdee4b4866287c2cfe9d89772a46c5d9d22377c8c63e43b2c93295
-
SHA512
2d365edfc61ed9610ad7caa9a82be757339214e91508e89a156ce118170a552291881c4527a22a397214c35839b2a12c04b20404274cc8624bf54308dc01d574
-
SSDEEP
6144:6ZLweyyWMa3NIBkL6LDW8dTZdw702edvxiuYOO6umz4:6ZLweyyHadIBkLIi8dTL2SvguYOO1mk
Malware Config
Extracted
Family
icedid
C2
ldrstar.casa
Signatures
-
IcedID First Stage Loader 1 IoCs
Processes:
resource yara_rule behavioral1/memory/3028-1-0x00000000744E0000-0x000000007456C000-memory.dmp IcedidFirstLoader -
Blocklisted process makes network request 34 IoCs
Processes:
rundll32.exeflow pid process 3 3028 rundll32.exe 4 3028 rundll32.exe 6 3028 rundll32.exe 7 3028 rundll32.exe 9 3028 rundll32.exe 10 3028 rundll32.exe 12 3028 rundll32.exe 13 3028 rundll32.exe 17 3028 rundll32.exe 18 3028 rundll32.exe 20 3028 rundll32.exe 21 3028 rundll32.exe 23 3028 rundll32.exe 24 3028 rundll32.exe 26 3028 rundll32.exe 27 3028 rundll32.exe 29 3028 rundll32.exe 30 3028 rundll32.exe 32 3028 rundll32.exe 33 3028 rundll32.exe 34 3028 rundll32.exe 35 3028 rundll32.exe 37 3028 rundll32.exe 38 3028 rundll32.exe 40 3028 rundll32.exe 41 3028 rundll32.exe 43 3028 rundll32.exe 44 3028 rundll32.exe 46 3028 rundll32.exe 47 3028 rundll32.exe 49 3028 rundll32.exe 50 3028 rundll32.exe 52 3028 rundll32.exe 53 3028 rundll32.exe -
Suspicious use of WriteProcessMemory 7 IoCs
Processes:
rundll32.exedescription pid process target process PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe PID 1068 wrote to memory of 3028 1068 rundll32.exe rundll32.exe
Processes
-
C:\Windows\system32\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\198895bd9f49e2dc78c0f82420bb6f87_JaffaCakes118.dll,#11⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\198895bd9f49e2dc78c0f82420bb6f87_JaffaCakes118.dll,#12⤵
- Blocklisted process makes network request