Analysis
-
max time kernel
148s -
max time network
150s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
16-06-2024 16:00
Static task
static1
Behavioral task
behavioral1
Sample
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe
Resource
win7-20240611-en
General
-
Target
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe
-
Size
408KB
-
MD5
b45cd50bd3d5db6cb3e5889b960fdfb7
-
SHA1
c45485a4eb8211269e1897ee018fb6d181744976
-
SHA256
d3f52b04b3bef1998a713fecaedd72571949ff4e62e83f54896a42e6e26582e7
-
SHA512
754b5c5d8228e0843d091613183bf4cf58b01088d88404196368ec040837cfb594b677c07b0d1b915937b2838b06af680471bf342bbac62dca442fd1b9f6803d
-
SSDEEP
6144:lcN+ZQW4GQUa7gLASsKOp4Wk2p4X1iPA8tPVPVahgxzKYLBeqxRp37B:+YCBUdUHp4Wk2pAUPoM11eUZ
Malware Config
Extracted
formbook
3.9
cu
auditingforgood.com
frndcoin.com
thisroadcycling.com
vjchicken.com
justinemendes.com
64nvnv.com
lisaardinnisfree.com
yacht2cruise.com
matkailuautohelsinki.com
com-unlock-privatesb.info
prostor-seo.com
weldesignscompany.com
regalrebel.love
absolutesecurityco.com
kuashidaisc.com
projectfelicity.com
network-security-alert.site
beginnerconcepts.com
beautyallabout.com
hanbanuo.com
bluecastlegames.net
aristocratdayton.com
mistimbee.info
boomerangroomvintage.com
pilot.ltd
businessbootcampaustin.com
flick.digital
befathering.com
watchmoviebit.info
xn--49s0lk6dd2oou4au00a.com
myviewfromthebike.net
brandexworld.com
kongergat.com
radiocoolers.com
gamenews2017.online
jensenzingenberg.com
popobremen.com
followthepolo.com
tan-cov.com
tavaragame.com
loterieducoin.com
584zun.info
danjordan.net
xn--fiq9bx48agqk.com
med10clinic.info
24economie.com
careerfocusedinstitute.com
mn1989.com
botox-schweiz.com
uzbnj.info
leovegaslotto.rocks
careeropportunitymanagement.com
skuikriuvurbr.net
directexpressservice.com
cypresslog.com
x-sn.com
dreamscapegarden.info
pro-tech.online
hamwarz.com
xn--2o2bp4w08j.com
istanbultabela.online
bissesar.com
badushop.com
integritywebservices.biz
vaxosyk.com
Signatures
-
Formbook payload 1 IoCs
Processes:
resource yara_rule behavioral2/memory/3540-2-0x0000000000400000-0x0000000000466000-memory.dmp formbook -
Suspicious behavior: EnumeratesProcesses 2 IoCs
Processes:
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exepid process 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe -
Suspicious use of FindShellTrayWindow 2 IoCs
Processes:
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exepid process 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe -
Suspicious use of SendNotifyMessage 2 IoCs
Processes:
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exepid process 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe -
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exepid process 3540 b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\b45cd50bd3d5db6cb3e5889b960fdfb7_JaffaCakes118.exe"1⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of SetWindowsHookEx