General

  • Target

    1a88e5dcaab3465a1507be7e4d2e8d60_JaffaCakes118

  • Size

    276KB

  • MD5

    1a88e5dcaab3465a1507be7e4d2e8d60

  • SHA1

    a74e80a675b577bc8921befae1d4673a0a5eb962

  • SHA256

    2096c404d709221eae23bdb1fbaff57d648c7d017ea97035882b9b97d55d1df1

  • SHA512

    7595c6b79e933c0ded226d4a9782a833e480ed694a495394096e88e7631eff327933027a342d9cb0ed6ce196682bf29276143c7bfb7c9c5c6692027a98323c1d

  • SSDEEP

    6144:/je8A8PTEX+ilM/KcDzIekFOLqByWtapaH4ofdgua8:/je8HLEXjWKccJO2Bleaap8

Score
10/10

Malware Config

Signatures

  • Blackmoon family
  • Detect Blackmoon payload 1 IoCs
  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 2 IoCs

    Checks for missing Authenticode signature.

Files

  • 1a88e5dcaab3465a1507be7e4d2e8d60_JaffaCakes118
    .rar
  • 155绿色软件站.url
    .url
  • QQ牧场宝贝.exe
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections

  • system.ini