Analysis
-
max time kernel
117s -
max time network
117s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
17-06-2024 06:10
Static task
static1
Behavioral task
behavioral1
Sample
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe
Resource
win7-20240508-en
General
-
Target
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe
-
Size
536KB
-
MD5
b721de24bb88a9fb9ae36f96b5ba899d
-
SHA1
8ec7af6d279cd2280533ebfb211024c6088775a4
-
SHA256
1c761d2f1d96caf7adfd8d3ff3ffe5115bd9c870f3942874f11505667526df3a
-
SHA512
b0ed2c65898175622f8b742c1af6a9f2794182d0789d6bba3887441b2eb803472cc831e10c1d2de9752f4ea86dd659a79a9fcba319bd92b7723ad3678af2077e
-
SSDEEP
12288:LAv4NKgAC01fLLrHWNqVhr5g/LbRnRVrIA:HnSLrHgcy/fVz
Malware Config
Extracted
formbook
3.9
j1
559015.top
itwasntscalable.com
butteredcrumb.com
3124kk.com
boxerar.com
myk33.com
transitionwithtiffany.com
whitfielddiffie.com
youjieyuwang.com
nw2hl.info
calderas-profesionales.com
scoreoutlook.com
haloukaka.com
mysosdoctor.com
sologoods.com
thehonestcannabist.com
litlight.online
diodkm.ink
mojilifemedia.com
774opebet.com
saintlshop.com
tdccfaith.com
playstationcases.com
salonsuiterelieffund.info
lagranjafoodtruck.com
thomaswoodlpros.com
www0199x.com
451vlo.info
germanyrama.com
mertyapimalzemeleri.com
forsyt.tech
lashliftcourses.run
elcafetaldonostia.com
pinzhou.net
amongst.biz
sofiaecs.com
asiatechcbrbs.com
ulzlfan.net
blockchainlogistics.today
smarterprotection.info
americanatheistsmagazine.com
idrfr.loan
graceminasian.com
godsdigger.biz
ticonix.net
utilitycollege.com
devilsadvocat.com
irenehollebrandse.com
calculus-group.com
americantkd.com
restaurantecundinamarques.com
chicagorefinancesales.com
infpixel.com
paypail.online
progenixsupplementplatinum.com
allenphilp.net
healthfocus.live
lockbrainbtc.com
www376234.com
mascotcontainer.com
ohsobeau.com
baharsariboga.com
dreamhun.site
zimmermannimoveis.com
dozceb.com
Signatures
-
Formbook payload 1 IoCs
Processes:
resource yara_rule behavioral1/memory/2928-4-0x0000000000400000-0x000000000048B000-memory.dmp formbook -
Suspicious behavior: EnumeratesProcesses 1 IoCs
Processes:
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exepid process 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe -
Suspicious use of FindShellTrayWindow 2 IoCs
Processes:
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exepid process 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe -
Suspicious use of SendNotifyMessage 2 IoCs
Processes:
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exepid process 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe -
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exepid process 2928 b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\b721de24bb88a9fb9ae36f96b5ba899d_JaffaCakes118.exe"1⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2928-2-0x00000000002D0000-0x00000000002D8000-memory.dmpFilesize
32KB
-
memory/2928-3-0x0000000076F91000-0x0000000077092000-memory.dmpFilesize
1.0MB
-
memory/2928-4-0x0000000000400000-0x000000000048B000-memory.dmpFilesize
556KB
-
memory/2928-5-0x0000000076F90000-0x0000000077139000-memory.dmpFilesize
1.7MB
-
memory/2928-7-0x00000000002D0000-0x00000000002D8000-memory.dmpFilesize
32KB
-
memory/2928-8-0x0000000076F90000-0x0000000077139000-memory.dmpFilesize
1.7MB