General

  • Target

    a8077adcaa2e0091662b2041130889f6_JaffaCakes118

  • Size

    404KB

  • MD5

    a8077adcaa2e0091662b2041130889f6

  • SHA1

    5278abe96db440247d3df4752c06fb609c9878dd

  • SHA256

    75b7bddef1a15ec5831eeb5abc12341bf4322456909906a81ffc62ef8d955d81

  • SHA512

    9d9d64d3e7210770948e9d2c5bfdcb460b88f148426b034b9a6f3d6f0b355e9c237a832886ef79b70d381875a5fd8e2d651ad707e18c7076ec278f092cc573c3

  • SSDEEP

    12288:l65f99I/Lknsr3FiStrHNW1UlERVWLFMenh:l+99ELknO3FiyNbCRVWL/h

Score
3/10

Malware Config

Signatures

  • Unsigned PE 7 IoCs

    Checks for missing Authenticode signature.

Files

  • a8077adcaa2e0091662b2041130889f6_JaffaCakes118
    .rar
  • PO#053497.pdf.exe
    .exe windows:4 windows x86 arch:x86

    4ea4df5d94204fc550be1874e1b77ea7


    Headers

    Imports

    Sections

  • $TEMP/274.5
  • $TEMP/29.opends60.dll
  • $TEMP/AsyncPictureBoxForm.jsl
  • $TEMP/Grammars.HxT
    .xml
  • $TEMP/Harmony
  • $TEMP/Local107627953addgroup2.gif
    .gif
  • $TEMP/SterletFiretrap.dll
    .dll windows:5 windows x86 arch:x86

    31f8d7608ac28f8e2c4da2401fcb9a56


    Headers

    Imports

    Exports

    Sections

  • $TEMP/WebDevWebServer.exe
    .xml
  • $TEMP/WebNavigationFrames.jsm
    .js
  • $TEMP/aspnetisapi.dll
    .dll windows:5 windows x86 arch:x86

    920e7b5dde568d9493b3eee85fcde552


    Headers

    Imports

    Exports

    Sections

  • $TEMP/autolayt.dll
    .dll windows:5 windows x86 arch:x86

    e0c75e651f6c97a0938a6233a5931725


    Headers

    Imports

    Exports

    Sections

  • $TEMP/coyote.exe
    .exe windows:5 windows x86 arch:x86

    b8848a4f4ce4477c977469ab423650aa


    Headers

    Imports

    Sections

  • $TEMP/cvtres.exe
    .exe windows:5 windows x86 arch:x86

    acab46bf2f1f805110b896684dbe541f


    Code Sign

    Headers

    Imports

    Sections

  • $TEMP/dhcpwins15.gif
  • $TEMP/disco.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • $TEMP/dvvscmdsK.HxK
    .xml
  • $TEMP/elfi386.xdc
  • $TEMP/emcmp.ko
    .elf linux x64
  • $TEMP/ieexec.exe
    .xml
  • $TEMP/ltv350qv.ko
    .elf linux x64
  • $TEMP/nqroasn.gif
    .gif
  • $TEMP/oledw9FileList.HxF
    .xml
  • $TEMP/picturemate4.xml
    .xml
  • $TEMP/sl-modem.py
  • $TEMP/soft-structuregrey.jpg
    .jpg
  • $TEMP/system-config-printer.rtupdate
    .vbs
  • $TEMP/templatestar.png
    .png
  • $TEMP/url.amf
  • $TEMP/vsslnui.dll
    .dll windows:5 windows x86 arch:x86


    Headers

    Sections

  • $TEMP/webbrowser.cpython-35.pyc
  • $TEMP/x-sony-sr2.xml
    .xml
  • $TEMP/x-tex.xml
    .xml