Behavioral task
behavioral1
Sample
403518179/TEXT2HTML13/UConvertClass.js
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
403518179/TEXT2HTML13/UConvertClass.js
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
403518179/TEXT2HTML13/text2html.exe
Resource
win7-20240220-en
Behavioral task
behavioral4
Sample
403518179/TEXT2HTML13/text2html.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
403518179/flashget1.exe
Resource
win7-20240508-en
Behavioral task
behavioral6
Sample
403518179/flashget1.exe
Resource
win10v2004-20240508-en
General
-
Target
1abbb6cb6985c8dce875dc21b7d40c5e_JaffaCakes118
-
Size
411KB
-
MD5
1abbb6cb6985c8dce875dc21b7d40c5e
-
SHA1
abeb048fe91c6e032a88b87aa82da2bbb1955237
-
SHA256
26baa4252ae3a62bb4eb2fa35c777637bdc15cc660b40ddc99eac73edc811956
-
SHA512
f8ec276beb3af41255fb73e803db70af69cf466ad2963a15dad59eefa930694f941afdca7ef03c40c62e7d8110a3e46df640d771431c64e435edb30f4f60bede
-
SSDEEP
6144:uZ5Thwqalk7grZqE9WRY/HXiKMm5Z96z/Tfs7A9lcFuos8NnhJWmseb612cl9a:yJ7alkMrZqEJi9oQ8icFt7hJWRDQ
Malware Config
Signatures
-
Processes:
resource yara_rule static1/unpack001/403518179/TEXT2HTML13/text2html.exe upx -
Unsigned PE 2 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/403518179/TEXT2HTML13/text2html.exe unpack001/403518179/flashget1.exe
Files
-
1abbb6cb6985c8dce875dc21b7d40c5e_JaffaCakes118.rar
-
403518179/TEXT2HTML13/Default.cfg
-
403518179/TEXT2HTML13/HTMLgenUnit.dfm
-
403518179/TEXT2HTML13/HTMLgenUnit.pas
-
403518179/TEXT2HTML13/TEXT2HTML.ini
-
403518179/TEXT2HTML13/Text2HTML.dpr
-
403518179/TEXT2HTML13/Text2HTML.res
-
403518179/TEXT2HTML13/UAbout.dfm
-
403518179/TEXT2HTML13/UAbout.pas
-
403518179/TEXT2HTML13/UAppOptions.pas
-
403518179/TEXT2HTML13/UConvertClass.pas.js
-
403518179/TEXT2HTML13/UConvertThread.pas
-
403518179/TEXT2HTML13/UCustomIni.pas
-
403518179/TEXT2HTML13/UGenDeclarations.pas
-
403518179/TEXT2HTML13/UHTMLOptions.pas
-
403518179/TEXT2HTML13/UHighLighter.pas
-
403518179/TEXT2HTML13/UIOOptions.pas
-
403518179/TEXT2HTML13/quakelogo.jpg.jpg
-
403518179/TEXT2HTML13/text2HTML.GID
-
403518179/TEXT2HTML13/text2HTML.cnt
-
403518179/TEXT2HTML13/text2HTML.hlp
-
403518179/TEXT2HTML13/text2html.exe.exe windows:1 windows x86 arch:x86
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
Sections
UPX0 Size: - Virtual size: 504KB
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
UPX1 Size: 285KB - Virtual size: 288KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 9KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
-
403518179/TEXT2HTML13/text2html.upl
-
403518179/flashget1.exe.exe windows:4 windows x86 arch:x86
3c0e70bfa5f73f1f1cef484e2bcb5bf8
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
Imports
kernel32
GetModuleHandleA
user32
MessageBoxA
Sections
Size: 34KB - Virtual size: 64KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 1024B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 2KB - Virtual size: 8KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 2KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 8KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
-
403518179/下载说明.htm.html .js polyglot