Analysis

  • max time kernel
    132s
  • max time network
    104s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 11:48

General

  • Target

    1b2db236bc601e5bcfb37e75133d5f68_JaffaCakes118.exe

  • Size

    123KB

  • MD5

    1b2db236bc601e5bcfb37e75133d5f68

  • SHA1

    429111ae13b49e9a127d7d8a5f319a7207110bc0

  • SHA256

    26d1b03adfe0bcd81726c84368eb34974e15c2ba86c515db56b39658f1c4b7f1

  • SHA512

    534e42b1daf2acb50a68cdfa727b22f3a1b991c8eaa9abf34e62600496a1c92b7292bcb19caef54795c08ed2ded40ba6079e151909ab816520baf259fef36c95

  • SSDEEP

    3072:xdbT6SQtLbaJAgn2JIJnDSBloRyQ4uB1lIou+Pzn:xdf6SQt/aJAbIJ6EyQ4OIou+b

Score
4/10

Malware Config

Signatures

  • Drops file in Windows directory 1 IoCs
  • Program crash 1 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\1b2db236bc601e5bcfb37e75133d5f68_JaffaCakes118.exe
    "C:\Users\Admin\AppData\Local\Temp\1b2db236bc601e5bcfb37e75133d5f68_JaffaCakes118.exe"
    1⤵
    • Drops file in Windows directory
    PID:2964
    • C:\Windows\SysWOW64\WerFault.exe
      C:\Windows\SysWOW64\WerFault.exe -u -p 2964 -s 264
      2⤵
      • Program crash
      PID:1048
  • C:\Windows\SysWOW64\WerFault.exe
    C:\Windows\SysWOW64\WerFault.exe -pss -s 360 -p 2964 -ip 2964
    1⤵
      PID:5092

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2964-0-0x0000000000400000-0x0000000000426000-memory.dmp
      Filesize

      152KB

    • memory/2964-2-0x0000000000400000-0x0000000000426000-memory.dmp
      Filesize

      152KB