Analysis

  • max time kernel
    121s
  • max time network
    125s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 07:49

General

  • Target

    1a7ec0ec87295ca93e967b78646b6832_JaffaCakes118.pdf

  • Size

    150KB

  • MD5

    1a7ec0ec87295ca93e967b78646b6832

  • SHA1

    67fdd6f9527f1dfac93b2f03cd8fd45c1505445c

  • SHA256

    bfe183c667b462495b176b975be8973bee3cb030966ac799ceae93cbdec4d230

  • SHA512

    1863fbb2045fae5ac83a6e52abba2f23f83c8621863daa940ae5d1cadafcdcc8e6ff080656fa36cef57ba2aeacc55a546c227cb833e58dfaa0a89783324be9b3

  • SSDEEP

    3072:xKmOVvZx3HW+mDdoeQha/SWRZVIewxDcXkjsd/Zi+aZ29sOqT3xn4vUbJ:UmOJHW+K6eQI/SgHIeycWsd/Zr9l+317

Score
1/10

Malware Config

Signatures

  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of SetWindowsHookEx 3 IoCs

Processes

  • C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
    "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\1a7ec0ec87295ca93e967b78646b6832_JaffaCakes118.pdf"
    1⤵
    • Suspicious behavior: GetForegroundWindowSpam
    • Suspicious use of SetWindowsHookEx
    PID:1852

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
    Filesize

    3KB

    MD5

    17cc137a7ff58df4270e9045fcae4aec

    SHA1

    a5c2da488b0831a911b2687f550f8869f3ff6b8e

    SHA256

    45ba92a332344016759dd7b440c26faa910704e33435af1058687ff0856327d5

    SHA512

    e356bea026acbfff79e81d8c1ab366685e3b2fe0d0c1433efbee9c1101f2ba1e7484e100fcb9527a91fdd68029165d55f0879cbe48be04a2616ee0078bcc693b