General

  • Target

    1825c3ea4b59cadb7d59f6ab4dfe9bff_JaffaCakes118

  • Size

    11.2MB

  • MD5

    1825c3ea4b59cadb7d59f6ab4dfe9bff

  • SHA1

    9b11e5637df36df74a99049594c9441f068c0707

  • SHA256

    3a4fdb3a9b8a659cc336159f9473b70d747c22a357920e8052b9621f2a789310

  • SHA512

    bbd1fda0f3e73284a7a11dfa8c44c512a1588cc20f88a67ab403bb608321840855d30752a053b29e40b4c86828b63e6d0370eb7cfcf7858ad88a2133efcf2f48

  • SSDEEP

    196608:ATSHflKvlz/1tcko57P7sbsdN91DT7p9kGRFLHeKCaYzYSb2DfanVpfR79fLgH88:ATGflK9z17sEqrfdTFLHJYzofMpnTgHH

Score
3/10

Malware Config

Signatures

  • Unsigned PE 13 IoCs

    Checks for missing Authenticode signature.

Files

  • 1825c3ea4b59cadb7d59f6ab4dfe9bff_JaffaCakes118
    .exe windows:5 windows x86 arch:x86

    be41bf7b8cc010b614bd36bbca606973


    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:5 windows x86 arch:x86

    039bcbc605477e8e87ec550c2e60e748


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UAC.dll
    .dll windows:4 windows x86 arch:x86

    0ef725341a4aecf8398c0e2132f38049


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:5 windows x86 arch:x86

    45d25ca52c312b2254c60dbcb30342d1


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:5 windows x86 arch:x86

    9ea5bdc8c90dfcffe309465c26c89758


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:5 windows x86 arch:x86

    8700d0ebbb41c81ea52718af1ab70a93


    Headers

    Imports

    Exports

    Sections

  • $WINDIR/INF/oem59.PNF
  • InterVpn/bin/InterVpn/3.exe
    .exe windows:6 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • InterVpn/bin/InterVpn/intervpn.exe
    .exe windows:5 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • InterVpn/bin/InterVpn/qwesy.vbs
    .vbs
  • InterVpn/bin/InterVpn/vruns.exe
    .exe windows:6 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • InterVpn/bin/japonia.ovpn
  • InterVpn/bin/liblzo2-2.dll
    .dll windows:4 windows x86 arch:x86

    4ec8215dfab42d6fac9d5da6dd9a0e21


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • InterVpn/bin/libpkcs11-helper-1.dll
    .dll windows:4 windows x86 arch:x86

    78f38ea04e255807de178a3cf42422fc


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • InterVpn/bin/openssl.exe
    .exe windows:4 windows x86 arch:x86

    1db84e1558a5e972eab79fec812039bf


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • InterVpn/bin/openvpn-gui.exe
    .exe windows:4 windows x86 arch:x86

    e338463e5db12dc0bb2b76cdae8c791d


    Code Sign

    Headers

    Imports

    Sections

  • InterVpn/bin/openvpn.exe
    .exe windows:4 windows x86 arch:x86

    8fbe1b3acb9e3a95f53d56bea5b81523


    Code Sign

    Headers

    Imports

    Sections

  • InterVpn/bin/openvpnserv.exe
    .exe windows:4 windows x86 arch:x86

    74f67c643bdc17372ab94952e04887a7


    Code Sign

    Headers

    Imports

    Sections

  • InterVpn/bin/superb.ovpn
  • InterVpn/bin/test.ovpn
  • InterVpn/bin/vpn850936802.ovpn
  • OpenVPN64/bin/libeay32.dll
    .dll windows:4 windows x64 arch:x64

    4109868595a2f7e6ef989e4c9d4dd677


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • OpenVPN64/bin/liblzo2-2.dll
    .dll windows:4 windows x64 arch:x64

    20f66903fa8abcac500e3191d97590f6


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • OpenVPN64/bin/libpkcs11-helper-1.dll
    .dll windows:4 windows x64 arch:x64

    9e5bf46a990c3445e09af3ed786cc488


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • OpenVPN64/bin/openssl.exe
    .exe windows:4 windows x64 arch:x64

    65a3c221baa0df882d3fd9c93049e5cd


    Code Sign

    Headers

    Imports

    Sections

  • OpenVPN64/bin/openvpn-gui.exe
    .exe windows:4 windows x64 arch:x64

    5c11ee86d5e29f38f82ae74989ae3f1c


    Code Sign

    Headers

    Imports

    Sections

  • OpenVPN64/bin/openvpn.exe
    .exe windows:4 windows x64 arch:x64

    d234bd6927798d8a016b08f37d071181


    Code Sign

    Headers

    Imports

    Sections

  • OpenVPN64/bin/openvpnserv.exe
    .exe windows:4 windows x64 arch:x64

    026b4a3ac73a34cd312432e8917248de


    Code Sign

    Headers

    Imports

    Sections

  • OpenVPN64/bin/ssleay32.dll
    .dll windows:4 windows x64 arch:x64

    8bee9317724fe73d6d10fec1e0f99dc2


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • System64Folder/DriverStore/FileRepository/oemwin2k.inf_amd64_5a1fec2fbbccefcc/oemwin2k.PNF
  • System64Folder/DriverStore/FileRepository/oemwin2k.inf_amd64_5a1fec2fbbccefcc/oemwin2k.inf
  • System64Folder/DriverStore/FileRepository/oemwin2k.inf_amd64_5a1fec2fbbccefcc/tap0901.cat
  • System64Folder/DriverStore/FileRepository/oemwin2k.inf_amd64_5a1fec2fbbccefcc/tap0901.sys
    .sys windows:6 windows x64 arch:x64

    741e65dbed0bdb03af558a33e0336da1


    Code Sign

    Headers

    Imports

    Sections

  • TAP-Windows/bin/addtap.bat
  • TAP-Windows/bin/deltapall.bat
  • TAP-Windows/bin/devcon.exe
    .exe windows:6 windows x64 arch:x64

    ce4a5cfcfb0452b87e013f07f4d59f9c


    Headers

    Imports

    Sections

  • TAP-Windows/bin/tapinstall.exe
    .exe windows:6 windows x86 arch:x86

    a7780e6241d40a319bbde667eb84065f


    Code Sign

    Headers

    Imports

    Sections

  • TAP-Windows/driver/OemVista.inf
  • TAP-Windows/driver/OemWin2k.inf
  • TAP-Windows/driver/tap0901.cat
  • TAP-Windows/driver/tap0901.sys
    .sys windows:6 windows x86 arch:x86

    e8e98f9c6dd2ed86b62e0eee9ae50433


    Headers

    Imports

    Sections

  • TAP-Windows64/bin/addtap.bat
  • TAP-Windows64/bin/deltapall.bat
  • TAP-Windows64/bin/devcon.exe
    .exe windows:6 windows x64 arch:x64

    ce4a5cfcfb0452b87e013f07f4d59f9c


    Headers

    Imports

    Sections

  • TAP-Windows64/driver/OemWin2k.inf
  • TAP-Windows64/driver/tap0901.cat
  • TAP-Windows64/driver/tap0901.sys
    .sys windows:6 windows x64 arch:x64

    741e65dbed0bdb03af558a33e0336da1


    Code Sign

    Headers

    Imports

    Sections

  • countries.tsv
  • memmgrset.dll
    .dll windows:1 windows x86 arch:x86

    e4f995c3b4cb09ef5bd7dbe9046c750f


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • stop_all.exe
    .exe windows:4 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • unins000.dat
  • unins000.exe
    .exe windows:1 windows x86 arch:x86


    Headers

    Sections

  • vpnpro.exe
    .exe windows:4 windows x86 arch:x86


    Code Sign

    Headers

    Exports

    Sections