General
-
Target
ae816597f9990952c8b6f523b64f24c9_JaffaCakes118
-
Size
1008KB
-
Sample
240615-p273ys1dpf
-
MD5
ae816597f9990952c8b6f523b64f24c9
-
SHA1
f6a8209eebb95669f4c1223d4abe02888bf54173
-
SHA256
98605f399585016ae41edcfbc496fa98225ad51928b26b9dff6261fbc09d7d7f
-
SHA512
0847a636793b165dc30e3269ecda30371d26700ab213f34432912662f32431d1be1a6c811184a68aa6b3455ba392285524e7366695b3db642cc7f897da03c0bc
-
SSDEEP
12288:jcZsEIkKatBE0nv8Po4GxxlZsEIkKatBE0nv8Po4Gxx1ko:AZZIkbBTEQ4UZZIkbBTEQ4Po
Static task
static1
Behavioral task
behavioral1
Sample
ae816597f9990952c8b6f523b64f24c9_JaffaCakes118.exe
Resource
win7-20240611-en
Malware Config
Extracted
formbook
4.1
k8b
happycampersevents.com
sdjlhbsbgc.com
stephenkapere.com
iammelissamay.com
westhillsterracepdx.com
exceptionalhospitals.com
newnongye.com
sfheli.com
ytalmorales.com
etkensigorta.com
trophemus-treasure-hunters.com
ppcreselleraccount.com
prelovedfashiontreasures.com
santrixpharma.com
ahwxshop.com
7sat.asia
pitadippers.com
citestaccnt1598634983.com
testcaresort.com
supportcorder.com
tataaiawellnessday.com
dekacoiffure.com
sasvisioninternational.com
theresegabriel.com
igraigrica.com
pbuckleyprojects.com
wintersmooncandleco.com
messi-and-ronaldo.com
localille.com
colunadeterca.info
joesellspa.com
mymvttbenefits.com
therbalfoodinv.com
roganjoshi.net
hoodiesandties.com
bearded.photography
torresmetalicas.com
slippefisc.com
thedifystudios.com
a17-os.com
1915dobbindr.com
ssmgaezp.icu
zhuce580.com
donotwaitmore.com
karunadupa.com
actamilbc.com
khalong.xyz
pricetagpulse.com
ibslns.com
fit-for-diving.com
bestweedeaterguides.net
afaalgen.com
escuelainteligente.com
cleanroomtelephone.com
pardisebrahimi.com
dagvauditoresconsultores.com
cordiumjewelry.com
10andrews.com
san-andreas.online
ssgasiaw.com
thicongmaitonhanoi.asia
liveeditionproductions.com
goodjointmobilecuts.com
illupified.com
glowtey.com
Targets
-
-
Target
ae816597f9990952c8b6f523b64f24c9_JaffaCakes118
-
Size
1008KB
-
MD5
ae816597f9990952c8b6f523b64f24c9
-
SHA1
f6a8209eebb95669f4c1223d4abe02888bf54173
-
SHA256
98605f399585016ae41edcfbc496fa98225ad51928b26b9dff6261fbc09d7d7f
-
SHA512
0847a636793b165dc30e3269ecda30371d26700ab213f34432912662f32431d1be1a6c811184a68aa6b3455ba392285524e7366695b3db642cc7f897da03c0bc
-
SSDEEP
12288:jcZsEIkKatBE0nv8Po4GxxlZsEIkKatBE0nv8Po4Gxx1ko:AZZIkbBTEQ4UZZIkbBTEQ4Po
-
Formbook payload
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Suspicious use of SetThreadContext
-