GetTSObject
Behavioral task
behavioral1
Sample
19cb2dd21b3b23c2190477008bc827ba_JaffaCakes118.dll
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
19cb2dd21b3b23c2190477008bc827ba_JaffaCakes118.dll
Resource
win10v2004-20240611-en
General
-
Target
19cb2dd21b3b23c2190477008bc827ba_JaffaCakes118
-
Size
108KB
-
MD5
19cb2dd21b3b23c2190477008bc827ba
-
SHA1
f74347ff46d1439454a847cfb7a6e8e59661486c
-
SHA256
1aa075db925f3da6520d15b5a582980b5ec08da347153aafdd3bd8c4de0ea72a
-
SHA512
415e968a24753a31fd48a9a7cfb0a10b0ee41708428471efecf61db814c7039940733988fa43241f15d8342c20db167e4ab589dd2bf59997a9f758fd0062dfd5
-
SSDEEP
1536:aD0WmFn06josLeXIwOyU3Fx9CLRtA7AkSLHiPuasCmg6sB2n0iGnE6R67SqcMpu:aDlmJ0ohwO7H9gRtA7WKuThKnE6I27M
Malware Config
Signatures
-
Processes:
resource yara_rule sample vmprotect -
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 19cb2dd21b3b23c2190477008bc827ba_JaffaCakes118
Files
-
19cb2dd21b3b23c2190477008bc827ba_JaffaCakes118.dll windows:4 windows x86 arch:x86
7f45798a91f428b0e55d726d704a4ed8
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
Imports
kernel32
CloseHandle
GetModuleHandleA
GetProcAddress
VirtualProtect
shlwapi
StrStrIA
Exports
Exports
Sections
.text Size: - Virtual size: 22KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rdata Size: - Virtual size: 3KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.data Size: - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 4KB - Virtual size: 904B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.vmp0 Size: - Virtual size: 3KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.vmp1 Size: - Virtual size: 45KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.vmp2 Size: 96KB - Virtual size: 94KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.reloc Size: 4KB - Virtual size: 100B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ