JGS7DecodeBlock
JGS7DecodeBlockQuery
JGS7DecodeCreate
JGS7DecodeDestroy
Static task
static1
Behavioral task
behavioral1
Sample
1692a228e15a624c65580c5bbf1b405a_JaffaCakes118.dll
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
1692a228e15a624c65580c5bbf1b405a_JaffaCakes118.dll
Resource
win10v2004-20240508-en
Target
1692a228e15a624c65580c5bbf1b405a_JaffaCakes118
Size
140KB
MD5
1692a228e15a624c65580c5bbf1b405a
SHA1
d011d97de781266aed50e8d39321170019e1ceea
SHA256
15299dff3396df99a37e0757645e1cdb62048ef62c3d60c44c4f982057df659b
SHA512
a54b8a5c931570b42fc58c955e5d54cf5f22161b630f799185854230c5b1b0d3294b6cba087fdc918a67a62f8fc54915ac810a04e26ac5fc50e65ad5617ba7d8
SSDEEP
3072:AGd5SMkaOa0SB9lI6NQ3TaI49gCxW24UydiXsvM+:fd58nSB3ZOaI4SCxW0DC
Checks for missing Authenticode signature.
Processes:
resource |
---|
1692a228e15a624c65580c5bbf1b405a_JaffaCakes118 |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
_adjust_fdiv
free
malloc
_initterm
DisableThreadLibraryCalls
JGS7DecodeBlock
JGS7DecodeBlockQuery
JGS7DecodeCreate
JGS7DecodeDestroy
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE