Analysis
-
max time kernel
118s -
max time network
123s -
platform
windows7_x64 -
resource
win7-20231129-en -
resource tags
arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 08:01
Behavioral task
behavioral1
Sample
1a87154929ca78d158f08bd529c11b8b_JaffaCakes118.pdf
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
1a87154929ca78d158f08bd529c11b8b_JaffaCakes118.pdf
Resource
win10v2004-20240611-en
General
-
Target
1a87154929ca78d158f08bd529c11b8b_JaffaCakes118.pdf
-
Size
14KB
-
MD5
1a87154929ca78d158f08bd529c11b8b
-
SHA1
f12fa99c2317e905ab9187f429c9c3a62be97108
-
SHA256
fac825866fa7f428b7842ca131c710fbcce83b9dd022816bdee4cc6761c4c964
-
SHA512
6c5a6dd7e79dc868d083d65f493803d12d4ad8bdc4a7bcee90bc9bace5b90f1121ed1b37ab15c2b1e7d871b43bc580a64d7da512ca70aed43702f654031185fa
-
SSDEEP
384:8P5uqkGLGz5vKfTrZK/W0EettPW3/q6yZUJ/5taZnhirLnFw+YO:Z9C/s/jdZy/5AZnWnr
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1420 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 4 IoCs
Processes:
AcroRd32.exepid process 1420 AcroRd32.exe 1420 AcroRd32.exe 1420 AcroRd32.exe 1420 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\1a87154929ca78d158f08bd529c11b8b_JaffaCakes118.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD565a010e2e936844ccd5a52d9efa1bcce
SHA10a57d74074921c4a46bb978fb27b89cab625bedf
SHA2561b3cd1ed7ebab493118426fb8cede28afe6b2a75dcb9491bb963cf5d9254ba2d
SHA5122aea910f6c1528355fb1b8c00cefb84560b9c906376c781bd8b839e18b1f24d20a1601eed3140e3b299ce38dd97f3a89a4a6ad6967f5cfe97b60013b4307c90e
-
memory/1420-0-0x0000000003EA0000-0x0000000003F16000-memory.dmpFilesize
472KB