c:\build\source\rpbrowserrecordplugin\rel32\nprpffbrowserrecordext.pdb
Static task
static1
Behavioral task
behavioral1
Sample
181ca9f6d79520405a6fc77e032169cc_JaffaCakes118.dll
Resource
win7-20240611-en
General
-
Target
181ca9f6d79520405a6fc77e032169cc_JaffaCakes118
-
Size
132KB
-
MD5
181ca9f6d79520405a6fc77e032169cc
-
SHA1
f6ccdab95acbfa79e797a160177e5a4298607d4b
-
SHA256
53b0c6e71d32d57944acf3bd0cab964038e689ca15ca095142f56dcf6d79e951
-
SHA512
6c33c447772b28a4f343691602f21e80ee97cb30d1bc63cffcb695960d85438d539f8980f9f7e56c9f501811d552379fce0a1c7920fa5a5f2663db72bbc9708d
-
SSDEEP
3072:FmXfaOtOiD0tFbOZwDwyszxcXht/hg8UkDb2:FmCOtOmEOoquhNhg8U
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 181ca9f6d79520405a6fc77e032169cc_JaffaCakes118
Files
-
181ca9f6d79520405a6fc77e032169cc_JaffaCakes118.dll windows:5 windows x86 arch:x86
a4a75ada6040b163c699413aaa9cd8fd
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
Imports
msvcr90
_initterm_e
_amsg_exit
_adjust_fdiv
__CppXcptFilter
_unlock
__dllonexit
_lock
_encode_pointer
_crt_debugger_hook
?terminate@@YAXXZ
?_type_info_dtor_internal_method@type_info@@QAEXXZ
__clean_type_info_names_internal
_except_handler4_common
_ismbblead
_initterm
realloc
free
malloc
wcsnlen
memcpy
memmove_s
_CxxThrowException
_decode_pointer
_encoded_null
_malloc_crt
memcpy_s
memset
strrchr
_onexit
kernel32
VirtualAlloc
InitializeCriticalSection
LeaveCriticalSection
EnterCriticalSection
GetProcessHeap
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
HeapDestroy
GetSystemTimeAsFileTime
GetCurrentProcessId
GetCurrentThreadId
QueryPerformanceCounter
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
InterlockedCompareExchange
InterlockedExchange
Sleep
LocalAlloc
LocalFree
GetCurrentProcess
GetTickCount
GetLastError
LoadLibraryW
FindResourceExA
FindResourceA
LoadResource
LockResource
SizeofResource
DisableThreadLibraryCalls
FreeLibrary
LoadLibraryA
GetProcAddress
RaiseException
GetModuleFileNameA
user32
GetSystemMetrics
CharNextA
SetWindowsHookExA
UnhookWindowsHookEx
advapi32
RegCreateKeyExA
RegSetValueExA
RegOpenKeyExA
RegCloseKey
shell32
SHGetFolderPathW
shlwapi
PathAppendW
Exports
Exports
NSGetModule
NSModule
RNCloseBrowserRecordExt
RNDispatchBrowserEvent
RNInitBrowserRecordExt
Sections
.text Size: 12KB - Virtual size: 11KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 9KB - Virtual size: 8KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 3KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 99KB - Virtual size: 98KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 8KB - Virtual size: 7KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ