General

  • Target

    1a2bedd15436c6bf168ca435bfc7e9fa_JaffaCakes118

  • Size

    3.2MB

  • MD5

    1a2bedd15436c6bf168ca435bfc7e9fa

  • SHA1

    10b20ee762c52bc68f010d57ea14262430a6313e

  • SHA256

    996e6000cebbcd231bb0ffb7c9dbe528c556d9e0081d38ecae0a6a10d432ce7d

  • SHA512

    fab563f86a9151550d7d0344e7f98e23713c530f76f8f3cf769d1a2727f1de6727449e83533271645eb8a2b6152abc9fd82400bfa9211a0de98ab75e7ccfe669

  • SSDEEP

    98304:KAXTR4Iqr84H0piOVlOkEECzZWygXjuVQm5c2kTekBez:tOxVH1OHOkEvXMSVd5cV6Oez

Score
7/10
upx

Malware Config

Signatures

  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 6 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 5 IoCs

Files

  • 1a2bedd15436c6bf168ca435bfc7e9fa_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    7fa974366048f9c551ef45714595665e


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/InstallOptions.dll
    .dll windows:4 windows x86 arch:x86

    b1cd0d78f652ce5fc63f0879371af012


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    2017f2acbdaa42ab3e4adeb8b4c37e7b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/ToolTips.dll
    .dll windows:4 windows x86 arch:x86

    04338c58e26f4ac6ae89608ac6276429


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/WebCtrl.dll
    .dll windows:4 windows x86 arch:x86

    edf01e434638f2238a21d45d26ed9a7d


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/header.bmp
  • $PLUGINSDIR/ioSpecial.ini
  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/modern-wizard.bmp
  • $PROGRAMFILES/hao123icon/hao123.ico
  • Baidu-TB-ASBar.exe
    .exe windows:4 windows x86 arch:x86

    b711f65a9aff6a22fb2f57f0ac8bda33


    Code Sign

    Headers

    Imports

    Sections

  • $PROGRAM_FILES/Baidu/ASBarBroker.exe
    .exe windows:4 windows x86 arch:x86

    8cb73f23fc4ffce04345bba981c347fe


    Code Sign

    Headers

    Imports

    Sections

  • $PROGRAM_FILES/Baidu/AddressBar.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    c6079cff13dd538f8c2b93227d9d6d6c


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • $PROGRAM_FILES/Baidu/Toolbar/BaiduBarX_Tmp/BaiduBarX.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    8a5151241d661d0fc763cad0cc4438a1


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • $PROGRAM_FILES/Baidu/Toolbar/BaiduBarX_Tmp/BarBroker.exe
    .exe windows:4 windows x86 arch:x86

    94f6cb58c75c90f3be7ae4e45c80a52d


    Code Sign

    Headers

    Imports

    Sections

  • $PROGRAM_FILES/Baidu/Toolbar/BaiduBarX_Tmp/rc.dll
    .dll windows:4 windows x86 arch:x86

    d811d71710ad58776155b7a8da1fa9db


    Code Sign

    Headers

    Imports

    Sections

  • $PROGRAM_FILES/Baidu/conf.xml
    .xml
  • Config/Top10.ini
  • Data/Apps/CoolTools/QQ±íÇé.ico
  • Data/Apps/CoolTools/QQ¿Õ¼ä´úÂë.ico
  • Data/Apps/CoolTools/QQ¿Õ¼äËزÄ.ico
  • Data/Apps/CoolTools/QQÔÚÏß²éѯ.ico
  • Data/Apps/CoolTools/Thumbs.db
  • Data/Apps/CoolTools/WebQQ.ico
  • Data/Apps/CoolTools/config.txt
  • Data/Apps/CoolTools/¸öÐÔÇ©Ãû.ico
  • Data/Apps/CoolTools/¹ÉƱÐÐÇé.ico
  • Data/Apps/CoolTools/ÃÀͼÐãÐã.ico
  • Data/Apps/CoolTools/Ë«É«Çò×ßÊÆ.ico
  • Data/Apps/CoolTools/ͼѾѾ.ico
  • Data/Apps/CoolTools/ÓÐȤ¸öÐÔÍ·Ïñ.ico
  • Data/Apps/CoolTools/ÔÚÏßPS.ico
  • Data/Apps/Lives/365ÈÕÀú.ico
  • Data/Apps/Lives/Thumbs.db
  • Data/Apps/Lives/Web·ÉÐÅ.ico
  • Data/Apps/Lives/config.txt
  • Data/Apps/Lives/douguo.ico
  • Data/Apps/Lives/±ØÓ¦´Êµä.ico
  • Data/Apps/Lives/²Ø×å¼ÇÕË.ico
  • Data/Apps/Lives/¶¨Ê±ÌáÐÑ.ico
  • Data/Apps/Lives/·¢ÐÍÉè¼Æ.ico
  • Data/Apps/Lives/·¨±¦Íø.ico
  • Data/Apps/Lives/·Ç³ÏÎðÈÅ.ico
  • Data/Apps/Lives/¹«½»²éѯ.ico
  • Data/Apps/Lives/»ð³µ»úƱ.ico
  • Data/Apps/Lives/¼ÇÕËÀ².ico
  • Data/Apps/Lives/¼ÒÎñ÷»×Ó.ico
  • Data/Apps/Lives/½¡¿µÊ±¿Ì.ico
  • Data/Apps/Lives/¿áѶÂÃÓÎ.ico
  • Data/Apps/Lives/ÃÀÈݹËÎÊ.ico
  • Data/Apps/Lives/ÃûÈËÃûÑÔ.ico
  • Data/Apps/Lives/ÄÖÖÓÌáÐÑ.ico
  • Data/Apps/Lives/ÊÔÒ¼ä.ico
  • Data/Apps/Lives/ÊÖ»ú³äÖµ.ico
  • Data/Apps/Lives/ÌìÆøÔ¤±¨.ico
  • Data/Apps/Lives/Íâ»ã¶Ò»».ico
  • Data/Apps/Lives/ÍòÄêÀú.ico
  • Data/Apps/Lives/ÍøËÙ²âÊÔ.ico
  • Data/Apps/Lives/лª×Öµä.ico
  • Data/Apps/Lives/ÓͺļÆËã.ico
  • Data/Apps/Lives/ÔÚÏßµØͼ.ico
  • Data/Apps/Lives/ÕË×å¼ÇÕË.ico
  • Data/Apps/Lives/Õä°®Íø.ico
  • Data/Apps/Lives/Ö°Òµ²âÊÔ.ico
  • Data/Apps/Lives/ÖÐÒ½ÌåÖÊ.ico
  • Data/Apps/Lives/Öܹ«½âÃÎ.ico
  • Data/Apps/Lives/×£¸£¶ÌÐÅ.ico
  • Data/Apps/News/Thumbs.db
  • Data/Apps/News/config.txt
  • Data/Apps/News/·ïÃùÐù.ico
  • Data/Apps/News/ºìÐäÌíÏã.ico
  • Data/Apps/News/»Ã½£ÊéÃË.ico
  • Data/Apps/News/ÆðµãÖÐÎÄÍø.ico
  • Data/Apps/News/Ìå̳Öܱ¨.ico
  • Data/Apps/News/×ݺáÖÐÎÄ.ico
  • Data/Apps/News/äìÏæÊéÔº.ico
  • Data/Apps/Videos/PPLIVEÁ¬Ðø¾ç.ico
  • Data/Apps/Videos/PPTVµçÊÓ¾ç.ico
  • Data/Apps/Videos/PPTVµçÓ°.ico
  • Data/Apps/Videos/Thumbs.db
  • Data/Apps/Videos/config.txt
  • Data/Apps/Videos/¶¹°êµç̨.ico
  • Data/Apps/Videos/¶àÃ×ÒôÀÖ.ico
  • Data/Apps/Videos/·ï»Ë¿íƵ.ico
  • Data/Apps/Videos/¸ßÇåµçÊǪ́.ico
  • Data/Apps/Videos/ºÃ°®ÊÕÒô»ú.ico
  • Data/Apps/Videos/¿áÁùÓ°ÊÓ.ico
  • Data/Apps/Videos/¿áÃ׶¯»­.ico
  • Data/Apps/Videos/èÀ´µçÊÓ.ico
  • Data/Apps/Videos/ÆæÒì¸ßÇå.ico
  • Data/Apps/Videos/ÈËÈ˵ç̨.ico
  • Data/Apps/Videos/ËѺü¸ßÇå.ico
  • Data/Apps/Videos/ÍÁ¶¹ÊÓƵ.ico
  • Data/Apps/Videos/ѸÀ׸ßÇå.ico
  • Data/Apps/Videos/ÒôÔĄ̃.ico
  • Data/Apps/Videos/ÔÆÊÓµçÊÓ.ico
  • Data/Apps/WebGames/Thumbs.db
  • Data/Apps/WebGames/config.txt
  • Data/Apps/WebGames/defaul.png
    .png
  • Data/Apps/WebGames/ÊÇÄÐÈ˾Í.ico
  • Data/Games/GAME.htm
    .html
  • Data/Games/YXZH.txt
  • Data/Games/config.txt
  • Data/Games/defaul.png
    .png
  • Data/MyUrls/RecomUrls.txt
  • Data/Nav1/DH1.htm
    .html
  • Data/Nav1/DH2.htm
    .html
  • Data/Nav1/DH3.htm
    .html
  • Data/Nav1/DH4.htm
    .html
  • Data/Nav1/DH5.htm
    .html
  • Data/Nav1/Nav1Ver.txt
  • Data/Nav1/SYCX.txt
  • Data/Taobao/360buy.png
    .png
  • Data/Taobao/GW.htm
    .html
  • Data/Taobao/SSGW.txt
  • Data/Taobao/Thumbs.db
  • Data/Taobao/config.txt
  • Data/Taobao/µ±µ±Íø.png
    .png
  • Data/Taobao/·²¿Í³ÏÆ·.png
    .png
  • Data/Taobao/ÌÔ±¦.png
    .png
  • Data/Taobao/ÌÔ±¦É̳Ç.png
    .png
  • Data/Taobao/׿ԽÍø.png
    .png
  • Data/Tools/PPSÍøÊÓ.ico
  • Data/Tools/RecomSofts.txt
  • Data/Tools/Software/ÓͺļÆËãÆ÷/Oil.dat
  • Data/Tools/Software/ÓͺļÆËãÆ÷/Oil.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • Data/Tools/Thumbs.db
  • Data/Tools/°Ù¶È°éÂÂ.ico
  • Qdesk.exe
    .exe windows:4 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • QdeskApp.exe
    .exe windows:4 windows x86 arch:x86


    Code Sign

    Headers

    Sections

  • uninst.exe
    .exe windows:4 windows x86 arch:x86

    7fa974366048f9c551ef45714595665e


    Code Sign

    Headers

    Imports

    Sections

  • $PLUGINSDIR/modern-header.bmp