CreateXmlReader
CreateXmlReaderInputWithEncodingCodePage
CreateXmlReaderInputWithEncodingName
CreateXmlWriter
CreateXmlWriterOutputWithEncodingCodePage
CreateXmlWriterOutputWithEncodingName
Static task
static1
Behavioral task
behavioral1
Sample
5d1acece864918cd32674b53b03b2782_JaffaCakes118.dll
Resource
win7-20240221-en
Target
5d1acece864918cd32674b53b03b2782_JaffaCakes118
Size
1.2MB
MD5
5d1acece864918cd32674b53b03b2782
SHA1
63818c48ec06eb1844c8a40bf931059664ec7473
SHA256
277cfe89b173e55243afc85867c0ccdf81b40800db1f16499c09544981a9ecfe
SHA512
d5024bb54815dc3162cda4bc5bfe81d8edc9f9356ee99de35ff17f01492c5e69026cc9ac31611719283b0e1ec3209501669b4b543ce4e6a9c275ca81b93845fa
SSDEEP
24576:vyTonNVlKTt/Q5ECvVP7hpJMvjtKpvPf9+m6kLRqgSyI:vyWRKTt/QlPVp3h9
Checks for missing Authenticode signature.
Processes:
resource |
---|
5d1acece864918cd32674b53b03b2782_JaffaCakes118 |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
InsertMenuW
DrawIconEx
DrawStateW
DrawTextW
GetCharWidthW
GetSystemPaletteEntries
GetTextExtentExPointI
GetCharWidth32A
GetViewportOrgEx
DeleteEnhMetaFile
GetWindowExtEx
FreeResource
FillConsoleOutputCharacterA
DeleteTimerQueueTimer
GetThreadId
LoadLibraryA
lstrcmpiW
GetPrivateProfileStringW
GetCurrentThread
GlobalDeleteAtom
VirtualAlloc
DebugActiveProcess
GetCommProperties
ConvertDefaultLocale
GetNLSVersion
GetLastError
GetThreadTimes
GetEnvironmentStringsW
GetSecurityDescriptorSacl
LookupAccountSidA
DecryptFileW
DeregisterEventSource
GetFileTitleW
CreateXmlReader
CreateXmlReaderInputWithEncodingCodePage
CreateXmlReaderInputWithEncodingName
CreateXmlWriter
CreateXmlWriterOutputWithEncodingCodePage
CreateXmlWriterOutputWithEncodingName
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ