Static task
static1
Behavioral task
behavioral1
Sample
bc4d2fd23a3ca94216443cea23381b54_JaffaCakes118.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
bc4d2fd23a3ca94216443cea23381b54_JaffaCakes118.exe
Resource
win10v2004-20240611-en
General
-
Target
bc4d2fd23a3ca94216443cea23381b54_JaffaCakes118
-
Size
816KB
-
MD5
bc4d2fd23a3ca94216443cea23381b54
-
SHA1
7f3c793c3c6414d223f5ce7d5090bb9dc2dcd709
-
SHA256
34e6ca7fcd9b02405980bd6a92e20b8f972b0988e90576135c4ce12216f12f7e
-
SHA512
4f7ede4877feccbeb063cf7a2c9bcfe5c9e31f0336800f92c42259153724682599d466aa7500f344c6c370e3b300b3dc3ee4212f00b655bddc2a79fbafe0d5e9
-
SSDEEP
12288:6crq243ICNz1TJ987E77JALCkUBmke6dfDKT2UD4w3E1/JoV0TCV+Z:6e4d1q7o7Bkz3NDSpyG6+Z
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource bc4d2fd23a3ca94216443cea23381b54_JaffaCakes118
Files
-
bc4d2fd23a3ca94216443cea23381b54_JaffaCakes118.exe windows:5 windows x86 arch:x86
2d927d8b51f84d530daacef2b8d0c48b
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
kernel32
VirtualAlloc
CreateEventW
FindNextFileW
OutputDebugStringA
GetVersionExA
CloseHandle
GetCurrentProcessId
CreateFileA
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
FlushFileBuffers
LCMapStringW
LCMapStringA
GetStringTypeW
MultiByteToWideChar
GetStringTypeA
GetLocaleInfoA
InitializeCriticalSectionAndSpinCount
LoadLibraryA
GetConsoleMode
GetConsoleCP
SetFilePointer
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
SetFileInformationByHandle
RtlUnwind
HeapReAlloc
GetSystemTimeAsFileTime
GetTickCount
QueryPerformanceCounter
VirtualFree
HeapCreate
DeleteCriticalSection
GetFileType
SetHandleCount
GetEnvironmentStringsW
WideCharToMultiByte
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetModuleFileNameA
GetStdHandle
ExitProcess
Sleep
LeaveCriticalSection
EnterCriticalSection
InterlockedDecrement
GetCurrentThreadId
SetLastError
GetLastError
FindFirstFileA
GetOverlappedResult
CreateFileW
ReadFile
CreateEventA
OpenProcess
AllocateUserPhysicalPages
WriteFile
GetProcessHeap
WaitForSingleObject
HeapFree
GetCurrentProcess
HeapAlloc
GetCommandLineW
GetModuleHandleA
CreateThread
ExitThread
InterlockedIncrement
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
GetProcAddress
GetModuleHandleW
RaiseException
GetStartupInfoA
GetCommandLineA
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
lstrcpyA
HeapSize
user32
ShowWindow
SetWindowTextA
DispatchMessageA
PostMessageA
EnableWindow
LoadCursorA
UpdateWindow
SendInput
GetTopWindow
IsClipboardFormatAvailable
GetParent
CreateMenu
EnumWindows
SetScrollRange
GetDC
TrackPopupMenuEx
AppendMenuW
GetWindowLongA
ReleaseDC
EnableMenuItem
GetDlgItem
GetSysColor
GetCursorPos
SetMenu
CreatePopupMenu
IsDlgButtonChecked
SystemParametersInfoA
LoadImageA
CountClipboardFormats
EndPaint
DrawTextA
LoadStringA
LoadIconA
GetClientRect
BeginPaint
TranslateAcceleratorA
EndDialog
LoadAcceleratorsA
IsWindow
DialogBoxParamA
DestroyWindow
GetMessageA
GetWindowRect
RegisterClassExA
PostQuitMessage
GetClassInfoExA
SetForegroundWindow
GetFocus
SetFocus
GetWindowTextLengthA
SendMessageA
TranslateMessage
GetWindowTextA
MessageBoxA
CreateWindowExA
DefWindowProcA
GetDesktopWindow
gdi32
CreateFontIndirectA
SetViewportOrgEx
SetWindowExtEx
SetTextColor
DeleteDC
CreateDIBSection
SelectObject
SelectClipRgn
CreateCompatibleDC
CombineRgn
FillRgn
GetObjectA
GetStockObject
CreateSolidBrush
DeleteObject
comdlg32
GetOpenFileNameA
ChooseFontA
shell32
CommandLineToArgvW
opengl32
wglCreateContext
wglMakeCurrent
version
GetFileVersionInfoW
psapi
GetProcessMemoryInfo
msvfw32
ICCompressorChoose
winmm
mmioSetInfo
mmioDescend
mmioSeek
mmioGetInfo
timeGetTime
iphlpapi
GetAdaptersAddresses
rpcrt4
UuidCreate
UuidToStringA
setupapi
SetupDiGetClassDevsA
tapi32
phoneClose
lineUnhold
Sections
.text Size: 103KB - Virtual size: 102KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 33KB - Virtual size: 32KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 6KB - Virtual size: 13KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 673KB - Virtual size: 672KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ