Static task
static1
Behavioral task
behavioral1
Sample
b0589f223333abed87ffc746672a6595_JaffaCakes118.exe
Resource
win7-20240611-en
General
-
Target
b0589f223333abed87ffc746672a6595_JaffaCakes118
-
Size
293KB
-
MD5
b0589f223333abed87ffc746672a6595
-
SHA1
6b058d76652e45e4d206e552be6ce1d66a5493f8
-
SHA256
6c067b7366e89e290c96deb271e18e8becf2f2ae0b83ad11a8254b226f109bb6
-
SHA512
df297bae84ead8bd10f02809da268094ec7e5a66d863a1eb2221d01762380daabbe61a91d0fdcfb0d0b8534a29d2ec3a3b30325047bb1b8fe38cced604140fc2
-
SSDEEP
6144:3s5dp/xuOu11LdlvrF/vG3UvGeDZkKMEY5RA:3slW1LPDFW3UvGwjY5RA
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource b0589f223333abed87ffc746672a6595_JaffaCakes118
Files
-
b0589f223333abed87ffc746672a6595_JaffaCakes118.exe windows:4 windows x86 arch:x86
6c3a2ba20248155bbbc368e1f038c10e
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Imports
dbnmpntw
ConnectionVer
ConnectionClose
ConnectionError
kernel32
MoveFileW
InterlockedDecrement
GetDiskFreeSpaceW
OpenMutexA
IsBadStringPtrW
GetProcAddress
GetCommandLineA
SetThreadContext
CreateHardLinkW
SetComputerNameW
lstrcat
GetConsoleTitleA
ReadConsoleW
lstrcmpiA
GetConsoleAliasW
CopyFileA
GetAtomNameA
FindFirstFileA
GetCommandLineW
GetProfileIntW
FormatMessageA
WaitForSingleObject
OpenFileMappingW
GetGeoInfoW
CreateThread
AddAtomA
LoadLibraryA
GetStartupInfoA
user32
GetClassNameA
InsertMenuA
RegisterClassExA
PostMessageA
LoadAcceleratorsA
FindWindowExW
LoadCursorA
IsCharUpperA
MessageBoxA
EndPaint
OemToCharA
clusapi
CloseClusterGroup
ClusterEnum
ClusterControl
cmpbk32
PhoneBookCopyFilter
PhoneBookFreeFilter
Sections
.text Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 3KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 281KB - Virtual size: 280KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ