General

  • Target

    6f2f7f2ce0ef33d170cf9ee67265770d_JaffaCakes118

  • Size

    4.2MB

  • MD5

    6f2f7f2ce0ef33d170cf9ee67265770d

  • SHA1

    beb2c4bd2ab65ed67028a1a8db92750c624d7eb8

  • SHA256

    4e459e942437ee7a6b767925f7cfaac795f9049c71b9211392061b2f4338dbfb

  • SHA512

    11e01409e4038e812f5351753f498e3a179d7a8e209f7d652682198796fab226406e4b613a669cac379513d689d0f920050d7a7e6a362470c5599169481b00fc

  • SSDEEP

    98304:BXDf8Q9Ymb74VAMgbMHWIZ/CA3VFSLVnqzGHsSM:BTf8QSSQiA2IZd3XUVnJ0

Score
3/10

Malware Config

Signatures

  • Unsigned PE 9 IoCs

    Checks for missing Authenticode signature.

Files

  • 6f2f7f2ce0ef33d170cf9ee67265770d_JaffaCakes118
    .exe windows:5 windows x86 arch:x86

    be41bf7b8cc010b614bd36bbca606973


    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:5 windows x86 arch:x86

    039bcbc605477e8e87ec550c2e60e748


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UAC.dll
    .dll windows:4 windows x86 arch:x86

    0ef725341a4aecf8398c0e2132f38049


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:5 windows x86 arch:x86

    45d25ca52c312b2254c60dbcb30342d1


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:5 windows x86 arch:x86

    9ea5bdc8c90dfcffe309465c26c89758


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:5 windows x86 arch:x86

    8700d0ebbb41c81ea52718af1ab70a93


    Headers

    Imports

    Exports

    Sections

  • Project1.dpr
  • Project1.res
  • Setup.exe
    .exe windows:6 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • Setupres.exe
    .exe windows:5 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • Unit1.pas
  • VMProtectSDK.pas
  • VMProtectSDK32.dll
    .dll windows:5 windows x86 arch:x86

    02e88351c3784f615719503b75919424


    Headers

    Imports

    Exports

    Sections

  • ipras.vbs
    .vbs