General
-
Target
1ddf5ea98e1a7dd64b545bf5b0a134c8_JaffaCakes118
-
Size
1.1MB
-
Sample
240702-d8kepatfmc
-
MD5
1ddf5ea98e1a7dd64b545bf5b0a134c8
-
SHA1
d7221d036405e8c0c225d1cc762dc4777ca4d490
-
SHA256
570be70a9bec91d08ca1ad0ad07d8b67964dbd7fbaee6623e1f724a3e86f2257
-
SHA512
a6dedbe0455e8c146f9370e46d947b08dacdfa26fc567b1d4fdfccff0effe0f00791421b3369259ce86e954e50448dfffc0c16dab1ef6d71d9eea051ace3845b
-
SSDEEP
24576:Bo782RtjAfL1HqeySA1MNrb+JOwVzBRutVGyWC1/Ngw0G:BojADUjjMNf+Jpl6VLdOG
Static task
static1
Behavioral task
behavioral1
Sample
1ddf5ea98e1a7dd64b545bf5b0a134c8_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1ddf5ea98e1a7dd64b545bf5b0a134c8_JaffaCakes118.exe
Resource
win10v2004-20240226-en
Malware Config
Targets
-
-
Target
1ddf5ea98e1a7dd64b545bf5b0a134c8_JaffaCakes118
-
Size
1.1MB
-
MD5
1ddf5ea98e1a7dd64b545bf5b0a134c8
-
SHA1
d7221d036405e8c0c225d1cc762dc4777ca4d490
-
SHA256
570be70a9bec91d08ca1ad0ad07d8b67964dbd7fbaee6623e1f724a3e86f2257
-
SHA512
a6dedbe0455e8c146f9370e46d947b08dacdfa26fc567b1d4fdfccff0effe0f00791421b3369259ce86e954e50448dfffc0c16dab1ef6d71d9eea051ace3845b
-
SSDEEP
24576:Bo782RtjAfL1HqeySA1MNrb+JOwVzBRutVGyWC1/Ngw0G:BojADUjjMNf+Jpl6VLdOG
Score10/10-
Modifies WinLogon for persistence
-
Sets service image path in registry
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Drops file in System32 directory
-