General

  • Target

    1aaef4e0e3f20a822942c519c7625e83_JaffaCakes118

  • Size

    1.3MB

  • MD5

    1aaef4e0e3f20a822942c519c7625e83

  • SHA1

    aacae6f9a7d99dea349bcf06b7c5f0e4505084f8

  • SHA256

    97a9006b85e59128c17b85a2e53395b125d4394ed325da83c990189bf8b7004c

  • SHA512

    0e9eb73d8b98e356547a4061e2ff645f73a2ffabcb42c035baeea81c1a915bb6b6ec055507f392c10c43830ea1d2611682e4ca17c0e55f682b152133144c01d3

  • SSDEEP

    24576:gXnDzCDE44x9zPLFCULo4pDyLqjkF6ukCCOkyXk9fF9aTjmm2jwsOyetr8lzXjb:4CnGlLFDOpX0F9aPm6sOyQr8lzXjb

Score
7/10
upx

Malware Config

Signatures

  • ACProtect 1.3x - 1.4x DLL software 2 IoCs

    Detects file using ACProtect software.

  • UPX packed file 2 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 17 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 4 IoCs

Files

  • 1aaef4e0e3f20a822942c519c7625e83_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    7fa974366048f9c551ef45714595665e


    Headers

    Imports

    Sections

  • $LOCALAPPDATA/bloson.bmp
  • $LOCALAPPDATA/facemoods.bmp
  • $LOCALAPPDATA/facemoods.exe
    .exe windows:4 windows x86 arch:x86

    7fa974366048f9c551ef45714595665e


    Code Sign

    Headers

    Imports

    Sections

  • $LOCALAPPDATA/Google/Chrome/User Data/default/Local Storage/chrome-extension_ihflimipbcaljfnojhhknppphnnciiif_0.localstorage
  • $PLUGINSDIR/ExtractDLLEx.dll
    .dll windows:4 windows x86 arch:x86

    bab48790663c56c456d63bc3e045f161


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/InetLoad.dll
    .dll windows:4 windows x86 arch:x86

    24a4a671f5cc294ce3543d18a1e873cd


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/NSISdl.dll
    .dll windows:4 windows x86 arch:x86

    9cce555dd3ff1b6c7dc92d64c794c51a


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/Processes.dll
    .dll windows:5 windows x86 arch:x86

    eaa5f91829171a65db414b9e64ec9548


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    2017f2acbdaa42ab3e4adeb8b4c37e7b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/UserInfo.dll
    .dll windows:4 windows x86 arch:x86

    afa8e526425f3585465337467d0b5909


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/chrmPref.dll
    .dll windows:4 windows x86 arch:x86

    93bde92aa23094d5545e87c4d138f2ba


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:4 windows x86 arch:x86

    1e2884056e655f2b7bc5a904e352fc80


    Headers

    Imports

    Exports

    Sections

  • $PROGRAMFILES/Mozilla Firefox/searchplugins/fcmdSrch.xml
  • $_34_/extensions/[email protected]/chrome.manifest
  • $_34_/extensions/[email protected]/components/FFHst.dll
    .dll windows:4 windows x86 arch:x86

    42265262b1570e7f94a9fb42ce88043e


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • $_34_/extensions/[email protected]/components/FFHst.xpt
  • $_34_/extensions/[email protected]/facemoods.jar
    .zip
  • content/facemoods.css
  • content/facemoods.xul
    .js
  • content/imgs/arwDwn.gif
    .gif
  • content/imgs/facemoods.png
    .png
  • content/imgs/pref.jpg
    .jpg
  • content/imgs/search.png
    .png
  • content/mtstart.js
    .js
  • content/prefLoader.js
    .js
  • content/preferences.xul
    .js .xml polyglot
  • content/tmplt.js
    .js
  • $_34_/extensions/[email protected]/install.rdf
    .xml
  • bh/facemoods.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    44f4d3d27a95aa836b9d7cbf6a70fcc2


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • facemoods.crx
    .zip
  • background.html
    .html .js polyglot
  • dropdown.html
    .html .js polyglot
  • img/128.png
    .png
  • img/16.png
    .png
  • img/32.png
    .png
  • img/48.png
    .png
  • img/64.png
    .png
  • img/ajax-loader.gif
    .gif
  • js/FMLoader.js
    .js
  • js/mtrprt.js
    .js
  • manifest.json
  • style/facemoods_chrome_1.0.1.css
  • facemoods.png
    .png
  • facemoodsApp.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    54c66c30640ceaf09d0e7010ae8bba2a


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • facemoodsEng.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    8b24b5fee3a50d84bb40a6cbf9737945


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • facemoodsTlbr.dll
    .dll regsvr32 windows:4 windows x86 arch:x86

    c5bd7ceec8c30d0cd7560ee6100655d6


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • facemoodssrv.exe
    .exe windows:4 windows x86 arch:x86

    5bb76c9b862d3d66ddbf9ae1fa74b496


    Code Sign

    Headers

    Imports

    Sections

  • uninstall.exe.nsis
  • $LOCALAPPDATA/lateral1.bmp
  • $LOCALAPPDATA/lateral2.bmp
  • $LOCALAPPDATA/lateral3.bmp
  • $PLUGINSDIR/LangDLL.dll
    .dll windows:4 windows x86 arch:x86

    9b6b6a7858e17fb0b17e1c1428330343


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    2017f2acbdaa42ab3e4adeb8b4c37e7b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/inetc.dll
    .dll windows:4 windows x86 arch:x86

    e886a412cdaf11998a8eeffda508e913


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/md5dll.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Exports

    Sections

  • out.upx
    .dll windows:4 windows x86 arch:x86


    Headers

    Sections

  • $PLUGINSDIR/modern-header.bmp
  • $PLUGINSDIR/nsDialogs.dll
    .dll windows:4 windows x86 arch:x86

    1e2884056e655f2b7bc5a904e352fc80


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/nsRandom.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Exports

    Sections

  • out.upx
    .dll windows:4 windows x86 arch:x86


    Headers

    Sections