Analysis
-
max time kernel
150s -
max time network
142s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 07:25
Static task
static1
Behavioral task
behavioral1
Sample
194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe
Resource
win7-20240221-en
General
-
Target
194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe
-
Size
58KB
-
MD5
194697fca36c6fa32dfc472045dc07df
-
SHA1
ca3335302134edadd3cf484d7cbbe487abb85e86
-
SHA256
f2ba64784d39ad6daa76b0f48a2399e713c9addf20538f77faed0ec6a2312025
-
SHA512
f538f650854abe789e7f559f441a732db4793130bee724a81dc85b4fb7d3dc845c9ac477e3393358f758cf4f1103f61142303fd88ee314f292a8654c55130837
-
SSDEEP
768:YV3iVRNSXbC1DNF5HJRmskyC88cds+G0cHtv0JOIYTNZUVCODhtp9M:Yuk8b5pcg9pgj4yZOD/c
Malware Config
Signatures
-
Modifies WinLogon for persistence 2 TTPs 1 IoCs
Processes:
svchost.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = "userinit.exe,c:\\program files (x86)\\microsoft\\desktoplayer.exe" svchost.exe -
Executes dropped EXE 1 IoCs
Processes:
DesktopLayer.exepid process 2808 DesktopLayer.exe -
Loads dropped DLL 2 IoCs
Processes:
194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exepid process 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe -
Processes:
resource yara_rule behavioral1/memory/1924-2-0x0000000000400000-0x0000000000415000-memory.dmp upx behavioral1/memory/2808-13-0x0000000000400000-0x0000000000415000-memory.dmp upx behavioral1/memory/2808-15-0x0000000000400000-0x0000000000415000-memory.dmp upx behavioral1/memory/2808-39-0x0000000000400000-0x0000000000415000-memory.dmp upx -
Drops file in System32 directory 2 IoCs
Processes:
svchost.exedescription ioc process File opened for modification C:\Windows\SysWOW64\dmlconf.dat svchost.exe File created C:\Windows\SysWOW64\dmlconf.dat svchost.exe -
Drops file in Program Files directory 64 IoCs
Processes:
svchost.exe194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exedescription ioc process File opened for modification C:\Program Files\Mozilla Firefox\lgpllibs.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\lua\http\mobile_browse.html svchost.exe File opened for modification C:\Program Files\Common Files\System\Ole DB\oledb32.dll svchost.exe File opened for modification C:\Program Files\Java\jre7\bin\glib-lite.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\it\System.Web.Entity.Design.Resources.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\access\libvcd_plugin.dll svchost.exe File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL svchost.exe File opened for modification C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\it\WindowsBase.resources.dll svchost.exe File opened for modification C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\bin\jstatd.exe svchost.exe File opened for modification C:\Program Files\Mozilla Firefox\api-ms-win-core-timezone-l1-1-0.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\stream_out\libstream_out_description_plugin.dll svchost.exe File opened for modification C:\Program Files\Windows Sidebar\Gadgets\Calendar.Gadget\ja-JP\calendar.html svchost.exe File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\1033\MSSOAPR3.DLL svchost.exe File opened for modification C:\Program Files\7-Zip\Uninstall.exe svchost.exe File opened for modification C:\Program Files\Common Files\Microsoft Shared\ink\mraut.dll svchost.exe File opened for modification C:\Program Files\Microsoft Office\Office14\MSOHEVI.DLL svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\fr\System.ServiceModel.Resources.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\ja\UIAutomationTypes.resources.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\fr\System.Data.Services.resources.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\access\libvdr_plugin.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\mux\libmux_ps_plugin.dll svchost.exe File opened for modification C:\Program Files\Common Files\System\DirectDB.dll svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\db\RELEASE-NOTES.html svchost.exe File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Esl\AiodLite.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll svchost.exe File opened for modification C:\Program Files\Windows Sidebar\Gadgets\Currency.Gadget\it-IT\currency.html svchost.exe File opened for modification C:\Program Files\Microsoft Games\Multiplayer\Spades\shvlzm.exe svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\it\PresentationBuildTasks.resources.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.IdentityModel.Selectors.dll svchost.exe File opened for modification C:\Program Files\Common Files\System\msadc\msadds.dll svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\plugins\com.jrockit.mc.console.ui.notification_5.5.0.165303\html\olh.htm svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\features\org.eclipse.help_2.0.102.v20141007-2301\license.html svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\it\System.Data.Services.Client.resources.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\demux\libasf_plugin.dll svchost.exe File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Office Setup Controller\pidgenx.dll svchost.exe File opened for modification C:\Program Files\Common Files\System\msadc\msdaremr.dll svchost.exe File opened for modification C:\Program Files\Google\Chrome\Application\106.0.5249.119\chrome_pwa_launcher.exe svchost.exe File opened for modification C:\Program Files\Microsoft Games\Multiplayer\Spades\ShvlRes.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\ja\PresentationCore.resources.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\it\System.Data.Entity.Resources.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\access_output\libaccess_output_srt_plugin.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\gui\libskins2_plugin.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\stream_out\libstream_out_cycle_plugin.dll svchost.exe File opened for modification C:\Program Files\Common Files\Microsoft Shared\ink\mshwgst.dll svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\jre\bin\prism-d3d.dll svchost.exe File opened for modification C:\Program Files\Windows Sidebar\Gadgets\Weather.Gadget\de-DE\settings.html svchost.exe File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.DLL svchost.exe File opened for modification C:\Program Files\Windows Media Player\wmpnscfg.exe svchost.exe File opened for modification C:\Program Files\Windows Sidebar\Gadgets\Clock.Gadget\es-ES\settings.html svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\axvlc.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\video_filter\libwave_plugin.dll svchost.exe File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\rt3d.dll svchost.exe File opened for modification C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\jre\bin\jsoundds.dll svchost.exe File opened for modification C:\Program Files\Java\jre7\bin\j2pcsc.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\UIAutomationClientsideProviders.dll svchost.exe File opened for modification C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\es\System.Windows.Presentation.resources.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\access\libnfs_plugin.dll svchost.exe File opened for modification C:\Program Files\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll svchost.exe File opened for modification C:\Program Files (x86)\Microsoft\DesktopLayer.exe 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\features\org.eclipse.emf.common_2.10.1.v20140901-1043\epl-v10.html svchost.exe File opened for modification C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\features\org.eclipse.ecf.filetransfer.feature_3.9.0.v20140827-1444\epl-v10.html svchost.exe -
Suspicious behavior: EnumeratesProcesses 4 IoCs
Processes:
DesktopLayer.exepid process 2808 DesktopLayer.exe 2808 DesktopLayer.exe 2808 DesktopLayer.exe 2808 DesktopLayer.exe -
Suspicious use of WriteProcessMemory 14 IoCs
Processes:
194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exeDesktopLayer.exedescription pid process target process PID 1924 wrote to memory of 2808 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe DesktopLayer.exe PID 1924 wrote to memory of 2808 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe DesktopLayer.exe PID 1924 wrote to memory of 2808 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe DesktopLayer.exe PID 1924 wrote to memory of 2808 1924 194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe DesktopLayer.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe PID 2808 wrote to memory of 2496 2808 DesktopLayer.exe svchost.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\194697fca36c6fa32dfc472045dc07df_JaffaCakes118.exe"1⤵
- Loads dropped DLL
- Drops file in Program Files directory
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\DesktopLayer.exe"C:\Program Files (x86)\Microsoft\DesktopLayer.exe"2⤵
- Executes dropped EXE
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\svchost.exeC:\Windows\system32\svchost.exe3⤵
- Modifies WinLogon for persistence
- Drops file in System32 directory
- Drops file in Program Files directory
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\features\org.eclipse.ecf.filetransfer.httpclient4.feature_3.9.1.v20140827-1444\epl-v10.htmlFilesize
128KB
MD569c58f2a2d990e050aae596a7d51fa56
SHA101d1b6c685bb26d41fe4e01c376e8feebb2236ea
SHA25656d1f7cad9e37a20b864a0233ca1197c7292c7f91c0b8ea2143e5b9ce9b7c8e5
SHA5120c4f2709b648f4fe1a4dc01f73fd463a9a661c6de4ef783e89b61afb86d22d4e6e6bf1ce29d6d6b5c083ff7ac61fb936af42b1558c0ef43ffc30e3726b071292
-
C:\Program Files\Java\jdk1.7.0_80\lib\missioncontrol\features\org.eclipse.ecf.filetransfer.httpclient4.feature_3.9.1.v20140827-1444\license.htmlFilesize
125KB
MD5c927a7a5f08ddc294c2c67be65fdd16d
SHA1516819dc15afe27be1f3a2fd52cb6e13c9a42a22
SHA2567aea38a2883f99324f41042a076c1e8027ec43588d52c9eee574427d18d8857d
SHA512d5f49ad199cbb0bba013b8f350c4d7f9c268925ad51c6772aa97fa2ae81921cd183f2a34290df1856054de2b064c29ce4eab12781d4201f04622dc82d80fbf5a
-
\Program Files (x86)\Microsoft\DesktopLayer.exeFilesize
58KB
MD5194697fca36c6fa32dfc472045dc07df
SHA1ca3335302134edadd3cf484d7cbbe487abb85e86
SHA256f2ba64784d39ad6daa76b0f48a2399e713c9addf20538f77faed0ec6a2312025
SHA512f538f650854abe789e7f559f441a732db4793130bee724a81dc85b4fb7d3dc845c9ac477e3393358f758cf4f1103f61142303fd88ee314f292a8654c55130837
-
memory/1924-0-0x0000000000220000-0x0000000000235000-memory.dmpFilesize
84KB
-
memory/1924-2-0x0000000000400000-0x0000000000415000-memory.dmpFilesize
84KB
-
memory/1924-10-0x0000000000220000-0x0000000000235000-memory.dmpFilesize
84KB
-
memory/2496-34-0x0000000000090000-0x0000000000091000-memory.dmpFilesize
4KB
-
memory/2496-37-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2496-17-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2496-23-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2496-28-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2496-33-0x0000000000080000-0x0000000000081000-memory.dmpFilesize
4KB
-
memory/2496-32-0x00000000000A0000-0x00000000000A1000-memory.dmpFilesize
4KB
-
memory/2496-19-0x0000000000080000-0x0000000000081000-memory.dmpFilesize
4KB
-
memory/2496-35-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2496-40-0x0000000020010000-0x000000002001E000-memory.dmpFilesize
56KB
-
memory/2808-39-0x0000000000400000-0x0000000000415000-memory.dmpFilesize
84KB
-
memory/2808-15-0x0000000000400000-0x0000000000415000-memory.dmpFilesize
84KB
-
memory/2808-14-0x0000000000240000-0x0000000000241000-memory.dmpFilesize
4KB
-
memory/2808-13-0x0000000000400000-0x0000000000415000-memory.dmpFilesize
84KB