General

  • Target

    79d775433be505a57ae175f5e6f427af_JaffaCakes118

  • Size

    4.5MB

  • MD5

    79d775433be505a57ae175f5e6f427af

  • SHA1

    32b9ac8255c3076841e658eabe581586ecdd8c8b

  • SHA256

    b7683441e42f706642877d1a92c5307d223b1e6195d463f1ad9332e7e6ac5a91

  • SHA512

    2c74529531c163ba9f768bf9aae97464aa5ddf2935c4085eb80d372a4e15d853bdfa46fc616b7b9b2e30730f4a484dfe3ba8b64188a3921faca589ffd379e7f7

  • SSDEEP

    98304:GAUlwbKKobLmzt3iOah1NBR595arTOLQZsxpzYazTd9e:GjCzViOSNL590r6Lys/zYuO

Score
3/10

Malware Config

Signatures

  • Unsigned PE 10 IoCs

    Checks for missing Authenticode signature.

Files

  • 79d775433be505a57ae175f5e6f427af_JaffaCakes118
    .exe windows:5 windows x86 arch:x86

    be41bf7b8cc010b614bd36bbca606973


    Headers

    Imports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:5 windows x86 arch:x86

    039bcbc605477e8e87ec550c2e60e748


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UAC.dll
    .dll windows:4 windows x86 arch:x86

    0ef725341a4aecf8398c0e2132f38049


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:5 windows x86 arch:x86

    45d25ca52c312b2254c60dbcb30342d1


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/modern-wizard.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:5 windows x86 arch:x86

    9ea5bdc8c90dfcffe309465c26c89758


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsExec.dll
    .dll windows:5 windows x86 arch:x86

    8700d0ebbb41c81ea52718af1ab70a93


    Headers

    Imports

    Exports

    Sections

  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/bin/addtap.bat
  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/bin/deltapall.bat
  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/bin/devcon.exe
    .exe windows:6 windows x64 arch:x64

    ce4a5cfcfb0452b87e013f07f4d59f9c


    Headers

    Imports

    Sections

  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/bin/tapinstall.exe
    .exe windows:6 windows x86 arch:x86

    a7780e6241d40a319bbde667eb84065f


    Code Sign

    Headers

    Imports

    Sections

  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/driver/OemVista.inf
  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/driver/OemWin2k.inf
  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/driver/tap0901.cat
  • $PROGRAMFILES/Ferr/SEDA/TAP-Windows/driver/tap0901.sys
    .sys windows:6 windows x86 arch:x86

    e8e98f9c6dd2ed86b62e0eee9ae50433


    Headers

    Imports

    Sections

  • $PROGRAMFILES/Ferr/SEDA/countries.tsv
  • $PROGRAMFILES/Ferr/SEDA/vpnpro.PTB.lng
  • $PROGRAMFILES/Ferr/SEDA/vpnpro.RUS.lng
  • Setup.exe
    .exe windows:6 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • Setupres.exe
    .exe windows:5 windows x86 arch:x86

    baa93d47220682c04d92f7797d9224ce


    Headers

    Imports

    Sections

  • ipras.vbs
    .vbs
  • ssleay32.dll
    .dll windows:4 windows x86 arch:x86

    9a578a896c8620e7ce2aaaca37343103


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • superb.ovpn
  • test.ovpn
  • vpn850936802.ovpn