C:\DOCUME~1\bld4act\LOCALS~1\Temp\Hpolaris\optPolaris\baseline\WMPBand.pdb
Static task
static1
Behavioral task
behavioral1
Sample
19367eed2b9fa4f92d399dc65f53d722_JaffaCakes118.dll
Resource
win7-20240611-en
General
-
Target
19367eed2b9fa4f92d399dc65f53d722_JaffaCakes118
-
Size
203KB
-
MD5
19367eed2b9fa4f92d399dc65f53d722
-
SHA1
144572e71d3145c88eed80843dd26eca471a1d09
-
SHA256
6833b923b4936c625222e68a923fa89afc17b4ae96821254dc7cdee9e1621a75
-
SHA512
48dc4b677c68077599827e02b00d87a74f5d83a9a4f16ead082cceaadd4ffd1e437d93984b0d9fb221ed63d4c824d7d520c92e40f5fcbfc382444cc01fbc21cd
-
SSDEEP
6144:BdTpountf75Iwj/CAVCf+8rOa/z0251PACi:7louhF/C+Cm8rOQ551/i
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 19367eed2b9fa4f92d399dc65f53d722_JaffaCakes118
Files
-
19367eed2b9fa4f92d399dc65f53d722_JaffaCakes118.dll regsvr32 windows:6 windows x86 arch:x86
cef4fbca5da8f1ceb161e89d7b681856
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
Imports
msvcrt
_wtoi
towupper
wcsstr
bsearch
iswdigit
wcsncmp
??_U@YAPAXI@Z
wcschr
wcspbrk
wcsrchr
_beginthreadex
_vsnwprintf
_wcsnicmp
towlower
iswspace
_wtol
_wcsicmp
_onexit
_lock
__dllonexit
_unlock
memmove
_adjust_fdiv
_amsg_exit
_initterm
_XcptFilter
??_V@YAXPAX@Z
memcpy
realloc
malloc
memset
??2@YAPAXI@Z
free
_purecall
??3@YAXPAX@Z
uxtheme
OpenThemeData
DrawThemeParentBackground
CloseThemeData
kernel32
SetErrorMode
CreateThread
WaitForSingleObject
CreateMutexW
DebugBreak
GetDriveTypeW
CreateFileW
WideCharToMultiByte
CloseHandle
DeviceIoControl
CreateFileA
GetVersion
GetLastError
lstrcpyW
InitializeCriticalSection
QueryDosDeviceW
InterlockedIncrement
InterlockedDecrement
LeaveCriticalSection
EnterCriticalSection
HeapDestroy
lstrlenW
GetModuleFileNameW
FreeLibrary
GetProcAddress
LoadLibraryW
GetVersionExW
VirtualProtect
VirtualAlloc
GetSystemInfo
VirtualQuery
MultiByteToWideChar
lstrcmpiW
RaiseException
lstrcpynW
lstrcatW
GlobalAddAtomW
GlobalDeleteAtom
lstrlenA
SizeofResource
LoadResource
FindResourceW
LoadLibraryExW
InterlockedExchange
Sleep
InterlockedCompareExchange
RtlUnwind
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetFileAttributesW
SetLastError
GetExitCodeThread
DeleteCriticalSection
ExpandEnvironmentStringsW
CompareStringW
CompareStringA
advapi32
RegQueryValueExW
TraceMessage
RegEnumKeyExW
RegEnumValueW
RegQueryInfoKeyW
RegSetValueExW
RegOpenKeyExW
RegCreateKeyExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
ole32
CreateStreamOnHGlobal
OleLockRunning
CoCreateInstance
CoTaskMemFree
StringFromGUID2
CoInitializeEx
CoUninitialize
CoMarshalInterface
CoUnmarshalInterface
RegisterDragDrop
RevokeDragDrop
CoTaskMemRealloc
CoTaskMemAlloc
oleaut32
VariantInit
VariantClear
SysStringLen
RegisterTypeLi
VarUI4FromStr
SysAllocString
SysFreeString
SysAllocStringLen
LoadRegTypeLi
VariantCopy
VariantChangeType
LoadTypeLi
user32
FillRect
SetForegroundWindow
CharPrevW
SetWindowPos
SendMessageW
EnumWindows
GetClassNameW
GetParent
FindWindowW
IsWindowVisible
ShowWindow
PostMessageW
CharNextW
LoadCursorW
RegisterClassW
CreateWindowExW
SetLayeredWindowAttributes
SetWindowLongW
BeginPaint
EndPaint
UnregisterClassW
DestroyAcceleratorTable
GetClientRect
CreateAcceleratorTableW
IsWindow
DestroyWindow
DefWindowProcW
InvalidateRgn
InvalidateRect
GetTopWindow
GetDC
SetFocus
GetFocus
KillTimer
IntersectRect
SetTimer
GetDesktopWindow
MonitorFromRect
GetMonitorInfoW
GetWindowLongW
GetWindow
GetWindowRect
EqualRect
SetRect
UnregisterHotKey
GetClassNameA
GetWindowThreadProcessId
SendMessageTimeoutA
GetAsyncKeyState
CharNextA
RegisterHotKey
IsIconic
ReleaseDC
GetCursorPos
gdi32
GetDeviceCaps
shell32
ShellExecuteExW
shlwapi
PathGetCharTypeW
PathGetCharTypeA
mpr
WNetAddConnection2W
WNetCancelConnection2W
WNetGetConnectionW
Exports
Exports
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
Sections
.text Size: 81KB - Virtual size: 81KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.data Size: 2KB - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 4KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 5KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
.text Size: 109KB - Virtual size: 112KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE