DllCanUnloadNow
DllGetClassObject
DllMain
DllRegisterServer
DllUnregisterServer
XllInit
Behavioral task
behavioral1
Sample
1a3f00647e9d0ded14fd961287e303d9_JaffaCakes118.dll
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
1a3f00647e9d0ded14fd961287e303d9_JaffaCakes118.dll
Resource
win10v2004-20240508-en
Target
1a3f00647e9d0ded14fd961287e303d9_JaffaCakes118
Size
71KB
MD5
1a3f00647e9d0ded14fd961287e303d9
SHA1
114198491f353a73bd2a2282822f99ea2d297e4a
SHA256
4be559d77e429be3b3eef40501e4170ba4fd9a64ce06c5c0d4a5cac05b095ca5
SHA512
3c395db39340a403212dedeed8a12f8cf3117780fac7d335c204a469936649d2d53f905966f60b297a5468b80db635dcf4bfc486e5c28a5e46fe6cfaf17a9f79
SSDEEP
1536:BztniZYykbpbX84Z5aOKTWTelbB8drn0N3aio7ULjE9qe5tEQ:BztiZ6X84Z5aOoWsed7mzqwE9qkZ
Detects file using ACProtect software.
Processes:
resource | yara_rule |
---|---|
sample | acprotect |
Processes:
resource | yara_rule |
---|---|
sample | upx |
Checks for missing Authenticode signature.
Processes:
resource |
---|
1a3f00647e9d0ded14fd961287e303d9_JaffaCakes118 |
unpack001/out.upx |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_BYTES_REVERSED_HI
DllCanUnloadNow
DllGetClassObject
DllMain
DllRegisterServer
DllUnregisterServer
XllInit
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ