Static task
static1
Behavioral task
behavioral1
Sample
b73ff4bd2c42f3ae83e9a54dc961e775_JaffaCakes118.exe
Resource
win7-20231129-en
General
-
Target
b73ff4bd2c42f3ae83e9a54dc961e775_JaffaCakes118
-
Size
308KB
-
MD5
b73ff4bd2c42f3ae83e9a54dc961e775
-
SHA1
b42270c0fc8af3d8ec5209d03d48af1075d1c059
-
SHA256
c783c92b42ced4137905d7c65180c9de8732fc48a2923036aad4f704f9630d26
-
SHA512
d5531830e6c8f6c2a9956d62f3cadac081fcf0e935848625bd994ad94414ce57f22fdeb0bdd48ac83644c1b80df07044ade4714dfcd9012b1bc37a68c5c713b5
-
SSDEEP
3072:tCPATouZdBAm8u5qvwuNPQItC7iykMPNPLlEg56pnvhEPcz/sjxOZe5:MPCum81YIPQMCuyDDlB25y4Ze5
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource b73ff4bd2c42f3ae83e9a54dc961e775_JaffaCakes118
Files
-
b73ff4bd2c42f3ae83e9a54dc961e775_JaffaCakes118.exe windows:4 windows x86 arch:x86
9a278b181cef195906f9a8436af01947
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Imports
user32
GetWindowRect
DialogBoxParamA
MessageBoxA
GetWindowTextA
EnableWindow
wsprintfA
GetDesktopWindow
SendMessageA
GetClientRect
GetSystemMetrics
SetWindowPos
EndDialog
GetDlgItem
SetWindowTextA
comdlg32
GetOpenFileNameA
msvcp60
??1_Winit@std@@QAE@XZ
??0_Winit@std@@QAE@XZ
??1Init@ios_base@std@@QAE@XZ
??0Init@ios_base@std@@QAE@XZ
?_Tidy@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEX_N@Z
?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
??Hstd@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@PBD@Z
?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB
?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z
??4?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV01@ABV01@@Z
??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
?size@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEIXZ
?c_str@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEPBDXZ
??6std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@0@AAV10@PBD@Z
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
msvcrt
_XcptFilter
exit
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
_exit
memset
malloc
strlen
free
__CxxFrameHandler
_EH_prolog
rewind
ftell
fseek
fclose
fopen
fread
fwrite
memcpy
strcpy
__dllonexit
_onexit
kernel32
GetStartupInfoA
GetModuleHandleA
Sections
.text Size: 124KB - Virtual size: 123KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 12KB - Virtual size: 11KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 108KB - Virtual size: 106KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 40KB - Virtual size: 38KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 16KB - Virtual size: 15KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ