d:\ccviews\autobuild1_br-0804-1355_15.9_snapshot\workingdirectory1\hdmiinstaller\1.1.12\installer\hdmi\release\coinstaller\igfxco32.pdb
Static task
static1
Behavioral task
behavioral1
Sample
178c7340ab0ce6b31fc4bc44cc393a5e_JaffaCakes118.dll
Resource
win7-20240419-en
General
-
Target
178c7340ab0ce6b31fc4bc44cc393a5e_JaffaCakes118
-
Size
240KB
-
MD5
178c7340ab0ce6b31fc4bc44cc393a5e
-
SHA1
6ff7edc898bde19ea47f93b0326c4051762a4902
-
SHA256
93bed0ccb9fd2c2936e83b757bc56f7b291132f7f0b0f6cf68d5b49cd580fc3e
-
SHA512
e1885fa858bc4eef00a5216d1ebaecb4cfe11ae1b78e3a3c827994319be9139b6dd5603e5138375b32f86345ad0bce856f120b5471797b720bc9cd0121c36162
-
SSDEEP
6144:Xxz/3Azb+fIX9Jpxyy3DzeuTs2vxfeTM:t2ii9JTNjJQM
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 178c7340ab0ce6b31fc4bc44cc393a5e_JaffaCakes118
Files
-
178c7340ab0ce6b31fc4bc44cc393a5e_JaffaCakes118.dll windows:4 windows x86 arch:x86
943233997454f9b782206c88165ce192
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
Imports
setupapi
SetupOpenInfFileA
SetupGetInfInformationA
SetupQueryInfOriginalFileInformationA
SetupDiGetDriverInfoDetailA
SetupDiGetSelectedDriverA
SetupDiGetDeviceRegistryPropertyA
SetupDiEnumDeviceInfo
SetupGetLineTextA
SetupCloseInfFile
SetupDiGetDeviceInstallParamsA
SetupDiGetClassDevsA
shlwapi
PathFindFileNameA
PathRemoveFileSpecA
PathAppendA
kernel32
CloseHandle
WaitForSingleObject
CreateProcessA
GetWindowsDirectoryA
CopyFileA
GetSystemDirectoryA
DeleteFileA
CreateFileA
FindNextFileA
FindClose
FindFirstFileA
GetCurrentProcess
GetProcAddress
GetModuleHandleA
GetVersionExA
TerminateProcess
FreeLibrary
LoadLibraryA
MultiByteToWideChar
GetLocalTime
GetModuleFileNameA
SetFileAttributesA
Sleep
SetFilePointer
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetStartupInfoA
GetFileType
SetHandleCount
InitializeCriticalSection
HeapSize
LCMapStringW
WideCharToMultiByte
LCMapStringA
GetOEMCP
GetACP
GetCPInfo
InterlockedDecrement
InterlockedIncrement
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
GetLastError
SetLastError
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
WriteFile
GetStdHandle
HeapReAlloc
VirtualAlloc
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
VirtualFree
HeapCreate
HeapDestroy
GetProcessHeap
GetCommandLineA
GetCurrentThreadId
ExitProcess
RtlUnwind
IsDebuggerPresent
LocalAlloc
InterlockedExchange
RaiseException
HeapFree
HeapAlloc
UnhandledExceptionFilter
SetUnhandledExceptionFilter
user32
DialogBoxParamA
LoadIconA
SendDlgItemMessageA
EndDialog
SetWindowPos
SendMessageA
SetDlgItemTextA
LoadStringA
SetFocus
gdi32
DeleteObject
CreateSolidBrush
CreateFontA
advapi32
RegQueryValueExA
RegDeleteValueA
RegEnumValueA
RegCreateKeyExA
RegSetValueExA
RegOpenKeyExA
RegEnumKeyExA
RegCloseKey
RegDeleteKeyA
shell32
SHCreateDirectoryExA
Exports
Exports
CoDeviceInstall
iAlmMFCoInstaller
Sections
.text Size: 92KB - Virtual size: 90KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rdata Size: 20KB - Virtual size: 19KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.data Size: 8KB - Virtual size: 11KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 100KB - Virtual size: 98KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 16KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ