Analysis
-
max time kernel
120s -
max time network
122s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 07:37
Behavioral task
behavioral1
Sample
13f2558ea23446b7493bec8bc48c4215_JaffaCakes118.pdf
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
13f2558ea23446b7493bec8bc48c4215_JaffaCakes118.pdf
Resource
win10v2004-20240611-en
General
-
Target
13f2558ea23446b7493bec8bc48c4215_JaffaCakes118.pdf
-
Size
79KB
-
MD5
13f2558ea23446b7493bec8bc48c4215
-
SHA1
efca97dba1321d6a855829380b9ce37d09a15d95
-
SHA256
7b7d5672fcaf9216667bea9040e51215d1cc68509a7adb4df512024e13781a40
-
SHA512
e6b469198f98ce2fdeba5e2b8b7d222716920d9e285a7762d103989c0fb3d866b40d5f9a4128a3ea146af650edc1865a4e24014fd13046b7dd52233171a43343
-
SSDEEP
1536:9po8KkzCJn/OCchTlXGq/+AlFSx3iHc74DNYfFWypOlLF/KwqOZWX4qnGId5EENI:I8K61Trmx3i8vWlLF//OtV5EENBZNfZU
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1964 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1964 AcroRd32.exe 1964 AcroRd32.exe 1964 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\13f2558ea23446b7493bec8bc48c4215_JaffaCakes118.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD53f2c633c5dd079bf1c5e3489fcf5f97a
SHA16b7dee64a8d88a75ea82f5d95d2d02bcae435abd
SHA256a352b2f6f3ce464fba287b868922c48ed773450afa4aaac41b72484d03fdd9fd
SHA5128c4a9d639d76b06a62a496e47cf30ed87831422ee33f014e60d6052fcb6c75238680405adba3100e8cda859e884a29970c0ea277b5f277e5804fc6572a41d010