Static task
static1
Behavioral task
behavioral1
Sample
b49cd0398cbc0e6cdfbab13cf0e53773_JaffaCakes118.exe
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
b49cd0398cbc0e6cdfbab13cf0e53773_JaffaCakes118.exe
Resource
win10v2004-20240226-en
General
-
Target
b49cd0398cbc0e6cdfbab13cf0e53773_JaffaCakes118
-
Size
2.2MB
-
MD5
b49cd0398cbc0e6cdfbab13cf0e53773
-
SHA1
565694a2ceb2ebbe0a49981c11adeb5cde244e76
-
SHA256
6e04fdd174b6d18769751acb97564e41b131ec95e00e9d92152f52969113b547
-
SHA512
32015420e4cb24c1d59de76e05fb8885069a8ef69dc7ab5bf60def9de503e7b6a7c78771b83b620eeb32b07e9173d10c267a237db62c55d19536761589528349
-
SSDEEP
49152:Es9J0weFq3/+GSoZxNqPaNQN64vjLFn1XA2mk/U:EkRHdZOPaNQnvjLF1P8
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource b49cd0398cbc0e6cdfbab13cf0e53773_JaffaCakes118
Files
-
b49cd0398cbc0e6cdfbab13cf0e53773_JaffaCakes118.exe windows:4 windows x86 arch:x86
baa93d47220682c04d92f7797d9224ce
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
Imports
kernel32
lstrcpy
comctl32
InitCommonControls
Sections
Size: 240KB - Virtual size: 540KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 337KB - Virtual size: 647KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 2.3MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
wbwimqcy Size: 1.7MB - Virtual size: 1.7MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
nslrcluv Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE