General

  • Target

    7d674a947b095c8c8c3a3cfa42ffe88a_JaffaCakes118

  • Size

    339KB

  • MD5

    7d674a947b095c8c8c3a3cfa42ffe88a

  • SHA1

    5b6865b9e2c3e2deb11d4582b54f1e55f8ec03cb

  • SHA256

    d618b457c1310790385c4efeb88e8afaa61876e42b17bc329bb148694a4b5a00

  • SHA512

    fcb5903f70c0ed65ccd8a1eb78e72af2df5ba63c14b87f66d352c031fbcba59f0387e6c2e15af4effe6da2fa399399651014b3fe62dab6fe36ca644cce5f40dd

  • SSDEEP

    6144:WPCganNaNG3j+Jx7DwGGuYBpar6n8z/w25BloiGjwoj6IkESqDLsM4REag:kansNGT+JxXwGQ828r/57PIDD7wlg

Score
3/10

Malware Config

Signatures

  • Unsigned PE 10 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • 7d674a947b095c8c8c3a3cfa42ffe88a_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    7c2c71dfce9a27650634dc8b1ca03bf0


    Headers

    Imports

    Sections

  • $APPDATA/sys/Office/36.opends60.dll
  • $APPDATA/sys/Office/51.opends60.dll
  • $APPDATA/sys/Office/MicrosoftVisualCVSCodeProvider.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • $APPDATA/sys/Office/RapiConfig.exe
    .exe windows:4 windows x86 arch:x86

    059f4f6cdf1fa06c9cdd00dd2fd90353


    Headers

    Imports

    Sections

  • $APPDATA/sys/Office/clstencilui.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Sections

  • $APPDATA/sys/Office/model34.xml
    .xml
  • $APPDATA/sys/Office/sbsmscordbi.dll
    .dll windows:5 windows x86 arch:x86

    67a93297e14b927bc8a7a8f49c55bfe1


    Headers

    Imports

    Sections

  • $APPDATA/test/formsend/27.opends60.dll
  • $APPDATA/test/formsend/46.opends60.dll
  • $APPDATA/test/formsend/VCTechNetLibsFilter80.xml
    .xml
  • $APPDATA/test/formsend/commentsbar.xml
    .xml
  • $APPDATA/test/formsend/msword.xml
    .xml
  • $APPDATA/test/formsend/octet-stream.xml
    .xml
  • $APPDATA/test/formsend/platformHTMLBindings.xml
    .xml
  • $APPDATA/test/formsend/regasm.exe
    .xml
  • $APPDATA/test/formsend/u25dts.dll
    .dll windows:4 windows x86 arch:x86

    ed0a9726fb75e6a4d15c49b3de416aa6


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • $APPDATA/test/formsend/vcbuild.dll
    .dll regsvr32 windows:5 windows x86 arch:x86

    692b68341529e63ad98e6e2f44d61598


    Headers

    Imports

    Exports

    Sections

  • $APPDATA/test/formsend/x-qtiplot.xml
    .xml
  • $TEMP/Heteroclite
  • $TEMP/RhetorEnthymeme.dll
    .dll windows:5 windows x86 arch:x86

    3eb017f3888fb33b139ff08304839d46


    Headers

    Imports

    Exports

    Sections

  • $TEMP/idbc/form/41.opends60.dll
  • $TEMP/idbc/form/ProcessParametersB.xml
  • $TEMP/idbc/form/org.gnome.settings-daemon.plugins.xsettings.gschema.xml
    .xml
  • $TEMP/lg/fun/Links/crtowordsit.dll
    .dll windows:4 windows x86 arch:x86

    aceaab6ff909512877330c9aa718c99d


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • $TEMP/lg/fun/Links/model106.xml
    .xml
  • $TEMP/trailer/Accessibility.xml
  • $TEMP/trailer/CMAccept.exe
  • $TEMP/trailer/SoapSudsCode.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • $TEMP/trailer/animations.xml
    .xml
  • $TEMP/trailer/model95.xml
    .xml
  • $TEMP/trailer/ordercloseactivity.xml
  • $TEMP/trailer/prox900.xml
    .xml
  • $TEMP/trailer/sbssystemconfigurationinstall.dll
    .dll windows:5 windows x86 arch:x86

    67a93297e14b927bc8a7a8f49c55bfe1


    Headers

    Imports

    Sections

  • $TEMP/trailer/vcbuildui.dll
    .dll windows:5 windows x86 arch:x86


    Headers

    Sections

  • $TEMP/trailer/x-troff-man.xml
    .xml