DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
Static task
static1
Behavioral task
behavioral1
Sample
1ac6a2d90e0ed718722153ea8782a4a3_JaffaCakes118.dll
Resource
win7-20240508-en
Target
1ac6a2d90e0ed718722153ea8782a4a3_JaffaCakes118
Size
786KB
MD5
1ac6a2d90e0ed718722153ea8782a4a3
SHA1
b5dd2b7c20330cbf13919e00ca35914e620e2285
SHA256
ed38f7a572415e5e1648f347a990fc3a3f2c4afcb3dd85e911277b27f866faca
SHA512
ee8c161578dce3ad261d7b67de7215debf9fb66d789a1dd495af7b4f941720b2e3eb8a0746467dd45b42e993326509dfafb2f5bf6180e1e161668b3bbc77d125
SSDEEP
24576:/SlFsJI3TOrQArNZOBXvhDkoR/WxG9uZZhUW2Slvt:/AyJI3T4QAx8LFMG9IwWdlvt
Checks for missing Authenticode signature.
Processes:
resource |
---|
1ac6a2d90e0ed718722153ea8782a4a3_JaffaCakes118 |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_BYTES_REVERSED_HI
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE