General

  • Target

    a5f96f5156a80dd9582387bac7ef188b_JaffaCakes118

  • Size

    167KB

  • MD5

    a5f96f5156a80dd9582387bac7ef188b

  • SHA1

    fdf80d175b06f4729b731fad71b6d60f923b508c

  • SHA256

    7a13dc4d9671646af3184f446ea94c7a29a4b84c36ca62b955ad625c52801520

  • SHA512

    3a143d06cabf241fc0d7ab2946213cf27e22e419461addaa780df7ada67b6aeba2eb48fa1d2c9d9b15af2ef83f876dc8e95d6643629b4720e35f1f659cefba8f

  • SSDEEP

    3072:HmQTncqxxcgQ9+jQR67PIKoETYyDcUC/iRO949pHVSg2IP9XnF:3TRxI+cR6LIIDcUuiRO672I9

Score
10/10

Malware Config

Extracted

Family

formbook

Version

3.9

Campaign

pe

Decoy

blackcatproud.com

kddgu.info

jhholiday.com

woshunwang.com

qrvou.info

yinuojie.com

404arabs.com

diaojieorg.com

hsyfjj.com

medusabotanicals.com

ghay5c.com

wm785.com

bikeandart.com

ygyroadside.info

whitewings.biz

4pointpartnersbv.com

tukangsedotwc.net

democrataward.com

systemtraffic2updating.win

thevlu.com

Signatures

  • Formbook family
  • Formbook payload 1 IoCs
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • a5f96f5156a80dd9582387bac7ef188b_JaffaCakes118
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections