Analysis
-
max time kernel
134s -
max time network
103s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
02-07-2024 10:23
Behavioral task
behavioral1
Sample
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe
Resource
win10v2004-20240611-en
General
-
Target
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe
-
Size
385KB
-
MD5
1ef7be727d7656f45d19cae632732fb4
-
SHA1
26d61d189673722854181594594a74348eb3a952
-
SHA256
948c1e7f771462f59f702de527e0ebf6c109bf9762284a9a54a91f08700d8404
-
SHA512
0b933f2a1a53840fef5deb834e6c8c22853910e6503d9f7191a91a3ac05722a225d1d17684107d5c6615356ece425b57b3aa7898cd066556f667954713356227
-
SSDEEP
6144:09BUwrQ9Ey4sxZZQttyCVxaWYSda4bHPS9x6qr6jDRPWHz6kp62kVCRjCK:GkEfeAtpVxag1bvgx6NdC62kVsjV
Malware Config
Signatures
-
Neshta
Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.
-
Checks computer location settings 2 TTPs 1 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-2447855248-390457009-3660902674-1000\Control Panel\International\Geo\Nation 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe -
Modifies system executable filetype association 2 TTPs 1 IoCs
Processes:
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\command\ = "C:\\Windows\\svchost.com \"%1\" %*" 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe -
Reads user/profile data of web browsers 2 TTPs
Infostealers often target stored browser data, which can include saved credentials etc.
-
Drops file in Program Files directory 64 IoCs
Processes:
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exedescription ioc process File opened for modification C:\PROGRA~3\PACKAG~1\{61087~1\VCREDI~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\READER~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jucheck.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jusched.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\1336~1.151\GOBD5D~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\DISABL~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\INTERN~1\ieinstal.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\EDGEUP~1\13147~1.37\MID1AD~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\ACROTE~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{63880~1\WINDOW~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\ADelRCP.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\LOGTRA~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Oracle\Java\javapath\javaws.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\1336~1.151\GOF5E2~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~4\wmpshare.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\Adobe\Setup\{AC76B~1\setup.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Java\JAVAUP~1\jaureg.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{4D8DC~1\VC_RED~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{CA675~1\VCREDI~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\ACROBR~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\1336~1.151\GO664E~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\ELEVAT~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Oracle\Java\javapath\javaw.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\1336~1.151\GOOGLE~2.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\PWAHEL~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\PWAHEL~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{D87AE~1\WINDOW~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\WOW_HE~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\EDGEUP~1\13147~1.37\MICROS~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~2\wabmig.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~4\setup_wm.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{57A73~1\VC_RED~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\arh.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\Eula.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Google\Update\1336~1.151\GOOGLE~4.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\EDGEUP~1\13147~1.37\MIA062~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~4\wmprph.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\AcroCEF\RdrCEF.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\Browser\WCCHRO~1\WCCHRO~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\plug_ins\PI_BRO~1\32BITM~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\msedge.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~3\ACCESS~1\wordpad.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~2\wab.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\Adobe\ACROBA~1\Reader\AcroRd32.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Adobe\ARM\1.0\ADOBEA~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\MICROS~1\VSTO\10.0\VSTOIN~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\MSEDGE~2.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\NOTIFI~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\EDGEUP~1\13147~1.37\MICROS~2.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MOZILL~1\UNINST~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WI8A19~1\ImagingDevices.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\Adobe\ARM\1.0\AdobeARM.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\INTERN~1\ExtExport.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\BHO\IE_TO_~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\msedge.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\MSEDGE~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\MSEDGE~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\WINDOW~4\wmplayer.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{EF5AF~1\WINDOW~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~3\PACKAG~1\{EF6B0~1\VCREDI~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\COMMON~1\MICROS~1\MSInfo\msinfo32.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\IDENTI~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MICROS~1\Edge\APPLIC~1\920902~1.67\INSTAL~1\setup.exe 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe File opened for modification C:\PROGRA~2\MOZILL~1\MAINTE~1.EXE 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe -
Drops file in Windows directory 1 IoCs
Processes:
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exedescription ioc process File opened for modification C:\Windows\svchost.com 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies registry class 1 IoCs
Processes:
1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exedescription ioc process Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\exefile\shell\open\command\ = "C:\\Windows\\svchost.com \"%1\" %*" 1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exe"1⤵
- Checks computer location settings
- Modifies system executable filetype association
- Drops file in Program Files directory
- Drops file in Windows directory
- Modifies registry class
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\PROGRA~2\Adobe\ACROBA~1\Reader\ACROTE~1.EXEFilesize
86KB
MD53d04dbf1008e99918f0cacc7e615ef0f
SHA1facf0a5106b6bc62f8a4a62b9d6d1af1a3ecf88a
SHA25644446e5e7031746091330058921b4a4850e7f1a7927056dc3ceefa118719dcf8
SHA5129cc19d3b9388970b117ce2e80e58aae8dcaf2258504ac804b947ccf653b18312aad7d0615f793d076731c317528bf82d70886ccc9898c861a907200ea5053699
-
C:\Users\Admin\AppData\Local\Temp\3582-490\1ef7be727d7656f45d19cae632732fb4_JaffaCakes118.exeFilesize
345KB
MD5bc6b4c28b3e8f86330f90b455d3c1cb7
SHA13f9b7ed22107ca62b044519fb061f5c3f8ffb9e0
SHA256144830d1829e194c3a34e65e20513f453f753f2898ac537a1fbbe392bc14c5fe
SHA512f8f98331c795a283a0d477772833a5532459fab9faf77b1e82c8362a8823bcac4fcc22b66b2ec695554782d2394c81b2e078ddcde902fc9d4017b15b727a26f9
-
memory/1020-91-0x0000000000400000-0x000000000041E000-memory.dmpFilesize
120KB
-
memory/1020-92-0x0000000000400000-0x000000000041E000-memory.dmpFilesize
120KB
-
memory/1020-94-0x0000000000400000-0x000000000041E000-memory.dmpFilesize
120KB