Analysis
-
max time kernel
118s -
max time network
118s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 12:34
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll
Resource
win7-20240508-en
3 signatures
150 seconds
General
-
Target
1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll
-
Size
139KB
-
MD5
1a216cce7475f2b00d19635e12d50a4d
-
SHA1
8cea09116d088459b2fcabb046b7806af494b824
-
SHA256
d357ea4f2a3928e761e91b8b705a937a854c2c8f32429c94ec5e81597bd5f174
-
SHA512
e9d02e27e7ec5b629ff86aa2c2eea309b6a10fcfd7d1c186748b11edf7e234807b81c2f17f2682a10fc70564dbb77eb789cfba61fd93df90909e0c02bc6ed7b9
-
SSDEEP
3072:4hp/c0R5+5jX0GyRTtJGnk9c3Pccc5QtPiO:oz8jzW3ACycc1
Malware Config
Signatures
-
Installs/modifies Browser Helper Object 2 TTPs 3 IoCs
BHOs are DLL modules which act as plugins for Internet Explorer.
Processes:
regsvr32.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{26D675AC-D925-4bbf-A720-62C2AA4A81EB} regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\ = "RivalGaming Games" regsvr32.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\NoExplorer = "1" regsvr32.exe -
Modifies registry class 60 IoCs
Processes:
regsvr32.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\Programmable regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ProxyStubClsid32 regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ = "IModule" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ProxyStubClsid32\ = "{00020424-0000-0000-C000-000000000046}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\0\win32\ = "C:\\Users\\Admin\\AppData\\Local\\Temp\\1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ = "IModule" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\0\win32 regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632} regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib\Version = "1.0" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\InprocServer32\ = "C:\\Users\\Admin\\AppData\\Local\\Temp\\1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\InprocServer32\ThreadingModel = "Apartment" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\TypeLib\ = "{275DA4CE-9717-4da7-B19B-490CB937718F}" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\FLAGS regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0 regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632} regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib\Version = "1.0" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F} regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib\ = "{275DA4CE-9717-4DA7-B19B-490CB937718F}" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ProxyStubClsid32 regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7} regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module.1\CLSID regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module.1\CLSID\ = "{26D675AC-D925-4bbf-A720-62C2AA4A81EB}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module\CLSID\ = "{26D675AC-D925-4bbf-A720-62C2AA4A81EB}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib\Version = "1.0" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\HELPDIR regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib\Version = "1.0" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ = "_IModuleEvents" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module\CurVer regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\ = "RivalGaming Games" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ProxyStubClsid32 regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\ProxyStubClsid32\ = "{00020424-0000-0000-C000-000000000046}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module.1\ = "RivalGaming Games" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\0 regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7} regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\TypeLib regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ProxyStubClsid32\ = "{00020420-0000-0000-C000-000000000046}" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module.1 regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module\CurVer\ = "RivalGaming.Module.1" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\ProgID regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\VersionIndependentProgID regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\HELPDIR\ = "C:\\Users\\Admin\\AppData\\Local\\Temp" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ProxyStubClsid32\ = "{00020420-0000-0000-C000-000000000046}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\TypeLib\ = "{275DA4CE-9717-4DA7-B19B-490CB937718F}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib\ = "{275DA4CE-9717-4DA7-B19B-490CB937718F}" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB} regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\ProgID\ = "RivalGaming.Module.1" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\FLAGS\ = "0" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\TypeLib\{275DA4CE-9717-4DA7-B19B-490CB937718F}\1.0\ = "RGLib Type Library" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ProxyStubClsid32 regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module\CLSID regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\VersionIndependentProgID\ = "RivalGaming.Module" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F03DA033-A35C-4F66-8849-5F68A181F632}\ = "_IModuleEvents" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DECB1BC9-7B19-411B-85B7-2B9FF33E2BE7}\TypeLib\ = "{275DA4CE-9717-4DA7-B19B-490CB937718F}" regsvr32.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\RivalGaming.Module\ = "RivalGaming Games" regsvr32.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26D675AC-D925-4bbf-A720-62C2AA4A81EB}\InprocServer32 regsvr32.exe -
Suspicious use of WriteProcessMemory 7 IoCs
Processes:
regsvr32.exedescription pid process target process PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe PID 3016 wrote to memory of 276 3016 regsvr32.exe regsvr32.exe
Processes
-
C:\Windows\system32\regsvr32.exeregsvr32 /s C:\Users\Admin\AppData\Local\Temp\1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\regsvr32.exe/s C:\Users\Admin\AppData\Local\Temp\1a216cce7475f2b00d19635e12d50a4d_JaffaCakes118.dll2⤵
- Installs/modifies Browser Helper Object
- Modifies registry class