Static task
static1
Behavioral task
behavioral1
Sample
01918229fcc186a1f44341d644f2c307_JaffaCakes118.exe
Resource
win7-20240220-en
General
-
Target
01918229fcc186a1f44341d644f2c307_JaffaCakes118
-
Size
144KB
-
MD5
01918229fcc186a1f44341d644f2c307
-
SHA1
d233c4775a805e1248947aa44d2cbaab52bdd98b
-
SHA256
db44be3f7cabe29a925594daae36ea68da4c4befde43e563e89af452872cd6d8
-
SHA512
5b066bc8c9fc2d24327284b4f0f46879a6d4e8ed5bf2fb0eafa91db1c392f435600674ea7f828ab3807e70bd5e9034354cb7a128d72760092ebd59eee7d49f6d
-
SSDEEP
1536:QMemdFFGZZwOWdUgos28BVEPRcTzU78XjXRRFyQ+6Iow28NLLlXqxK+PfpF6+oHX:BdOAOVF8wWH2cjBn+063lyKGn6vHdt
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 01918229fcc186a1f44341d644f2c307_JaffaCakes118
Files
-
01918229fcc186a1f44341d644f2c307_JaffaCakes118.exe windows:5 windows x86 arch:x86
c06450480ddd58a6fecea32c379062bd
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
rasapi32
RasSetEapUserDataA
gdi32
EndPath
Polygon
advapi32
AddUsersToEncryptedFile
winscard
SCardListCardsA
user32
RemovePropA
IsClipboardFormatAvailable
GetInputState
IntersectRect
GetAsyncKeyState
GetThreadDesktop
msvcrt
memset
oleaut32
VarCyFromUI4
VARIANT_UserSize
VarCyFromR8
setupapi
SetupQueryInfVersionInformationW
mprapi
MprConfigInterfaceGetHandle
clusapi
ClusterResourceCloseEnum
pdh
PdhGetFormattedCounterValue
kernel32
GetConsoleCP
GetVersion
GetConsoleOutputCP
GlobalMemoryStatusEx
FreeConsole
GetCurrentActCtx
UnhandledExceptionFilter
EnumSystemLocalesW
HeapCreate
GetThreadId
Sections
.text Size: 92KB - Virtual size: 91KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.data Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.idata Size: 4KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
CODE Size: 32KB - Virtual size: 28KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 4KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ