General

  • Target

    1e3f53e84c4b775c4c2a878646322437_JaffaCakes118

  • Size

    175KB

  • MD5

    1e3f53e84c4b775c4c2a878646322437

  • SHA1

    1032ca03b76d4a70710586727c04829d8c2d1bd4

  • SHA256

    3232b9c652b076fea2197921d592b735ff839069a6e7cc0a6efa9f3fc9b8dd5b

  • SHA512

    3b9fe424a1f42caf27452aa3e3b261e9e2a561f1b65296f2d1ff3dc629ad06c451d0a28c80752379bfc0f626a2fec6675bfa4a6b46be648e9f5583da589fb3da

  • SSDEEP

    3072:oVl2ChzxzTMlI0frxJLgf7nDVF6PUp1Yo3ICgxgV:iBhzxJex5gfzDVlVXgaV

Score
10/10

Malware Config

Extracted

Family

metasploit

Version

encoder/shikata_ga_nai

Extracted

Family

metasploit

Version

windows/shell_reverse_tcp

C2

127.0.0.1:4444

Signatures

  • Metasploit family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 1e3f53e84c4b775c4c2a878646322437_JaffaCakes118
    .exe windows:6 windows x86 arch:x86

    2a141685bec588fb7b12c50a8a40eb2b


    Headers

    Imports

    Sections