Static task
static1
Behavioral task
behavioral1
Sample
bb7b70fcd01eb0903c7ecf2a8a50cbea_JaffaCakes118.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
bb7b70fcd01eb0903c7ecf2a8a50cbea_JaffaCakes118.exe
Resource
win10v2004-20240508-en
General
-
Target
bb7b70fcd01eb0903c7ecf2a8a50cbea_JaffaCakes118
-
Size
713KB
-
MD5
bb7b70fcd01eb0903c7ecf2a8a50cbea
-
SHA1
22694b981fe9c6c9bedd6045299b55e564ebf8e8
-
SHA256
dacddfaece889da8a311107c5923313c6682acce5c718b5ae49550a1e15b24d0
-
SHA512
64ac24534d043b01dafad22f79af7649443c5dcd809fadeeac7faa08c04b1e73f33230e9f8d2824dfd90bedb30222c61f8490b7ee307ac753b146978a799c54e
-
SSDEEP
12288:8d8z9JklKqDlVGzfLPQU4dFC19BqR0o8lPFaV0pJVAyp5tAiRmKz:8Wpgc7yFC19Bs+tpJV5RmK
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource bb7b70fcd01eb0903c7ecf2a8a50cbea_JaffaCakes118
Files
-
bb7b70fcd01eb0903c7ecf2a8a50cbea_JaffaCakes118.exe windows:5 windows x86 arch:x86
b167643097689b30fe38415259b3ff30
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
CreateMutexW
GetLocaleInfoA
GetModuleHandleW
GetConsoleTitleA
WriteFile
FindResourceExA
SetSystemPowerState
SetConsoleTitleA
GetHandleInformation
GetProcAddress
LocalAlloc
SetConsoleWindowInfo
GetModuleHandleA
GetCurrentProcessId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
Sleep
ExitProcess
GetCommandLineA
GetStartupInfoA
GetLastError
GetStdHandle
GetModuleFileNameA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
SetHandleCount
GetFileType
DeleteCriticalSection
SetFilePointer
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapFree
CloseHandle
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
VirtualAlloc
HeapReAlloc
CreateFileA
SetStdHandle
FlushFileBuffers
HeapSize
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
Sections
.text Size: 637KB - Virtual size: 637KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.data Size: 32KB - Virtual size: 35.5MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.hab Size: 512B - Virtual size: 1B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.ker Size: 1024B - Virtual size: 963B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.rsrc Size: 41KB - Virtual size: 40KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ