Static task
static1
Behavioral task
behavioral1
Sample
95cc84b83fe02e3b970397634b300816_JaffaCakes118.exe
Resource
win7-20240221-en
General
-
Target
95cc84b83fe02e3b970397634b300816_JaffaCakes118
-
Size
276KB
-
MD5
95cc84b83fe02e3b970397634b300816
-
SHA1
a5b419e570136866d793d51bc498731aa51edbe6
-
SHA256
57efc1dfb758d4ed2c550e44ac01e93c71d2eaf7b0d8b4b7fd364d6f5069d9e8
-
SHA512
7df460dc6d9cc38e9e088dd6a772ebc69150d5ce158c48b20a58b88839f1fbda4f7b97afa2d1cbf9954d0efeb73cf3105d0653882ebd6a5527a3e14293479111
-
SSDEEP
6144:dytBFn2yUMVlmPR6bBre2XjBH77SAhEy:MLFnX5VwR81HXjBbFh
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 95cc84b83fe02e3b970397634b300816_JaffaCakes118
Files
-
95cc84b83fe02e3b970397634b300816_JaffaCakes118.exe windows:5 windows x86 arch:x86
2c3f929ae7719ed8b5c5474cbeb2434e
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
ws2_32
shutdown
secur32
DeleteSecurityContext
shlwapi
GetMenuPosFromID
advapi32
EqualDomainSid
IsWellKnownSid
gdi32
GetPixel
GetOutlineTextMetricsA
FillPath
GetPath
DeleteDC
GetBitmapBits
GetSystemPaletteUse
GetDeviceCaps
GetObjectW
GetClipRgn
winspool.drv
FindNextPrinterChangeNotification
oleaut32
LoadTypeLi
user32
GetWindowPlacement
GetWindowRect
GetMenuItemInfoW
GetClassInfoExA
MessageBoxIndirectA
InsertMenuA
IsWindow
GetProcessWindowStation
GetClipboardFormatNameW
EnumWindowStationsW
EqualRect
LoadMenuA
FillRect
GetThreadDesktop
powrprof
GetPwrCapabilities
IsPwrHibernateAllowed
kernel32
EraseTape
LockFile
FormatMessageW
GetModuleHandleA
GetDefaultCommConfigA
GetCPInfo
LocalLock
GetLocaleInfoA
FindResourceExW
GetDiskFreeSpaceExA
GetLocaleInfoW
GetVolumePathNameW
ExpandEnvironmentStringsW
GlobalHandle
GetProfileSectionW
GlobalLock
GetFileAttributesExW
GlobalFindAtomA
GetProcessAffinityMask
GetUserDefaultLCID
GetCommandLineW
FindFirstFileA
FindNextVolumeW
LoadLibraryExA
EnumSystemLocalesA
GetProcAddress
DeleteTimerQueue
LoadLibraryExW
LoadLibraryW
LocalReAlloc
LocalFileTimeToFileTime
GetPrivateProfileStructA
GetCurrencyFormatA
GlobalGetAtomNameW
DeleteVolumeMountPointW
FillConsoleOutputAttribute
GetConsoleCursorInfo
GetACP
GlobalAddAtomW
msvcrt
fputc
malloc
strspn
ftell
fseek
toupper
wininet
FindFirstUrlCacheGroup
FindNextUrlCacheGroup
Sections
.text Size: 20KB - Virtual size: 17KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.idata Size: 20KB - Virtual size: 18KB
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.data Size: 220KB - Virtual size: 219KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rsrc Size: 4KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 4KB - Virtual size: 812B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ