Overview
overview
8Static
static
31aa6ab5705...18.exe
windows7-x64
71aa6ab5705...18.exe
windows10-2004-x64
7$PLUGINSDI...NS.dll
windows7-x64
3$PLUGINSDI...NS.dll
windows10-2004-x64
3$PLUGINSDI...NU.dll
windows7-x64
3$PLUGINSDI...NU.dll
windows10-2004-x64
3$PLUGINSDI...EM.dll
windows7-x64
3$PLUGINSDI...EM.dll
windows10-2004-x64
3$TEMP/Fox-...ER.exe
windows7-x64
8$TEMP/Fox-...ER.exe
windows10-2004-x64
8SWF2MP3.chm
windows7-x64
1SWF2MP3.chm
windows10-2004-x64
1SWF2MP3.exe
windows7-x64
1SWF2MP3.exe
windows10-2004-x64
1SWF2MP3.url
windows7-x64
6SWF2MP3.url
windows10-2004-x64
3ºº»¯Ï...¡.url
windows7-x64
5ºº»¯Ï...¡.url
windows10-2004-x64
1ºüÀêÉ...í.url
windows7-x64
6ºüÀêÉ...í.url
windows10-2004-x64
3жÔØÈí¼þ.exe
windows7-x64
7жÔØÈí¼þ.exe
windows10-2004-x64
7Analysis
-
max time kernel
149s -
max time network
154s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 08:45
Static task
static1
Behavioral task
behavioral1
Sample
1aa6ab57058b1fa13bf2ce33358d43f3_JaffaCakes118.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
1aa6ab57058b1fa13bf2ce33358d43f3_JaffaCakes118.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/INSTALLOPTIONS.dll
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/INSTALLOPTIONS.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral5
Sample
$PLUGINSDIR/STARTMENU.dll
Resource
win7-20240611-en
Behavioral task
behavioral6
Sample
$PLUGINSDIR/STARTMENU.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral7
Sample
$PLUGINSDIR/SYSTEM.dll
Resource
win7-20240419-en
Behavioral task
behavioral8
Sample
$PLUGINSDIR/SYSTEM.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
$TEMP/Fox-Temp/IEHELPER.exe
Resource
win7-20240508-en
Behavioral task
behavioral10
Sample
$TEMP/Fox-Temp/IEHELPER.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral11
Sample
SWF2MP3.chm
Resource
win7-20240611-en
Behavioral task
behavioral12
Sample
SWF2MP3.chm
Resource
win10v2004-20240611-en
Behavioral task
behavioral13
Sample
SWF2MP3.exe
Resource
win7-20240220-en
Behavioral task
behavioral14
Sample
SWF2MP3.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
SWF2MP3.url
Resource
win7-20240611-en
Behavioral task
behavioral16
Sample
SWF2MP3.url
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
ºº»¯Ïà¹ØÎÊÌâ·´À¡.url
Resource
win7-20240611-en
Behavioral task
behavioral18
Sample
ºº»¯Ïà¹ØÎÊÌâ·´À¡.url
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
ºüÀêÉÙÒ¯ºº»¯×÷Æ·Áбí.url
Resource
win7-20240508-en
Behavioral task
behavioral20
Sample
ºüÀêÉÙÒ¯ºº»¯×÷Æ·Áбí.url
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
жÔØÈí¼þ.exe
Resource
win7-20240419-en
Behavioral task
behavioral22
Sample
жÔØÈí¼þ.exe
Resource
win10v2004-20240508-en
General
-
Target
SWF2MP3.exe
-
Size
264KB
-
MD5
8be4bd8d7ca73646339626f7a4f3a960
-
SHA1
a4fe8585d3a9b1ac118b0a1fa8a83551f086b2a4
-
SHA256
5ac4fbb96ec0b0a348c5e27709d87532a5f3a2fd89b9848beb6add9a3b7974c4
-
SHA512
03621e53a6cbd10093638408b1ce98dc150a7c8055cd7d453965f3947d37a049da9a4cb8c4e2efe5f5a2aaafd5226ad78c8402cd8f29a818a0ddac2a0e00efc3
-
SSDEEP
6144:K4Eepht6dqvz282sI8RlPVwwCViPf0lGreL9:KGaWy84S5Vw60lZZ
Malware Config
Signatures
-
Modifies registry class 3 IoCs
Processes:
SWF2MP3.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EA3290D9-F501-43FF-B112-A6B8D2CD068} SWF2MP3.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EA3290D9-F501-43FF-B112-A6B8D2CD068}\HTSTMC = d418b69b1dc17cbd2db5cdacf4d07ca01c55589d0625b66dd5ccfc6467310000b42f4a88dacc8c9678438734884c000097b3ae3f265d000024ca5e9c SWF2MP3.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EA3290D9-F501-43FF-B112-A6B8D2CD068}\InprocServer32 SWF2MP3.exe -
Suspicious use of SetWindowsHookEx 2 IoCs
Processes:
SWF2MP3.exepid process 1528 SWF2MP3.exe 1528 SWF2MP3.exe