JgedCreate
JgedDestroy
JgedDisableComponent
JgedDuplicate
JgedEnableComponent
JgedProcess
JgedSetOption
JgedStart
Static task
static1
Behavioral task
behavioral1
Sample
174b25d32b3f5f5bb16b4ca63ce6cd4d_JaffaCakes118.dll
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
174b25d32b3f5f5bb16b4ca63ce6cd4d_JaffaCakes118.dll
Resource
win10v2004-20240611-en
Target
174b25d32b3f5f5bb16b4ca63ce6cd4d_JaffaCakes118
Size
168KB
MD5
174b25d32b3f5f5bb16b4ca63ce6cd4d
SHA1
c75e56ea9b8e9cfadd48250e96482c4ed62959cb
SHA256
16efe8a5e457fd9b20de2382eda45030bbb08b94050f337cfe2d5de33168fc15
SHA512
ed243a8899734ce1afe7ea9276b2cbc670e0ceca843e3bef1213b7f73332f6cc508e566cf7963c90d91ddd684eee9fee0d578226d88a2b3fb3d5e4c457f50a4f
SSDEEP
3072:D61Ye3TaEu2CoCcn3zO7A4D8X03T5B0m65ecNYkSWtXIH2EF8E62fQuXUh2uR/Ys:+Ta12CoCckAe8+T5ILukSWtYWEHhXch3
Checks for missing Authenticode signature.
Processes:
resource |
---|
174b25d32b3f5f5bb16b4ca63ce6cd4d_JaffaCakes118 |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
_initterm
_adjust_fdiv
malloc
memmove
free
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
FreeLibrary
SetErrorMode
LoadLibraryA
GetProcAddress
JgedCreate
JgedDestroy
JgedDisableComponent
JgedDuplicate
JgedEnableComponent
JgedProcess
JgedSetOption
JgedStart
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE