Analysis
-
max time kernel
119s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 14:24
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
1ba1dafaad9de091019841ce7d0edf3f_JaffaCakes118.dll
Resource
win7-20240611-en
1 signatures
150 seconds
Behavioral task
behavioral2
Sample
1ba1dafaad9de091019841ce7d0edf3f_JaffaCakes118.dll
Resource
win10v2004-20240611-en
3 signatures
150 seconds
General
-
Target
1ba1dafaad9de091019841ce7d0edf3f_JaffaCakes118.dll
-
Size
20KB
-
MD5
1ba1dafaad9de091019841ce7d0edf3f
-
SHA1
9d807b602a12be5c0427b3513b54126452aa232e
-
SHA256
62318cab7413fd37529cea54d54ec19263a65e93efb3ec2bafc7e57dd0ab11bb
-
SHA512
d75031436ae6e10d6ab320f0fc2ffe65f3f18127ed4deded07dbfb1225fded363395435df113fba70692fdb2a48c62248b0d6598c98654e9935b89c0184349c7
-
SSDEEP
384:isUE2n+FbSBha+12uZrL/G675ZiKYWg/Ts5xLs/foNc2wmCqtwzI4:qjn+F0hai2gLn6KYImyc2wmxSzz
Score
1/10
Malware Config
Signatures
-
Suspicious use of WriteProcessMemory 7 IoCs
Processes:
regsvr32.exedescription pid process target process PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe PID 2108 wrote to memory of 2396 2108 regsvr32.exe regsvr32.exe
Processes
-
C:\Windows\system32\regsvr32.exeregsvr32 /s C:\Users\Admin\AppData\Local\Temp\1ba1dafaad9de091019841ce7d0edf3f_JaffaCakes118.dll1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\regsvr32.exe/s C:\Users\Admin\AppData\Local\Temp\1ba1dafaad9de091019841ce7d0edf3f_JaffaCakes118.dll2⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2396-0-0x00000000001A0000-0x00000000001C4000-memory.dmpFilesize
144KB