Static task
static1
Behavioral task
behavioral1
Sample
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118.exe
Resource
win10v2004-20240611-en
General
-
Target
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118
-
Size
244KB
-
MD5
1bc5c9316e96c1e084c637324adb5ab4
-
SHA1
5b0e20005021e8535463eb368114f7fe8dd09733
-
SHA256
4d5103192e78425daa38b2bf589d44d22a1081d8993af9d8830d15b686a508f3
-
SHA512
27e09570a1f7cb8eb6da61264de59f584befc10616151fddaf32d431a8c02e716a98bf137f32a6ab72d19b2363e7e14e8c2a5caaa1b67c75fb769c3c14b121a4
-
SSDEEP
6144:VtDO5bDO5XZXxS97mkWJ9HGeF2V+YXxH1MitwfV1Q:a525pXqSkWJBJTIHufVC
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118
Files
-
1bc5c9316e96c1e084c637324adb5ab4_JaffaCakes118.exe windows:4 windows x86 arch:x86
38e8923337ca68a165a0dead00bdb129
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Imports
msvbvm60
MethCallEngine
EVENT_SINK_AddRef
DllFunctionCall
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ord711
ord606
ord717
ProcCallEngine
ord644
ord570
ord100
ord616
Sections
.text Size: 36KB - Virtual size: 35KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.data Size: - Virtual size: 2KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 32KB - Virtual size: 29KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ