Static task
static1
Behavioral task
behavioral1
Sample
203faeab73cd2cb1e4e588bc0628b8b0_JaffaCakes118.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
203faeab73cd2cb1e4e588bc0628b8b0_JaffaCakes118.exe
Resource
win10v2004-20240508-en
General
-
Target
203faeab73cd2cb1e4e588bc0628b8b0_JaffaCakes118
-
Size
380KB
-
MD5
203faeab73cd2cb1e4e588bc0628b8b0
-
SHA1
6d1692b64010b050f09ada59fb4a717aecdfce2c
-
SHA256
01fe98d1464dc41e6bb58188655dd4bc1f969726c6a7e5b2b1c88d52914a3742
-
SHA512
ddfdc090b41f419844d8e6c35c7dc411b3335ed516d9d25bd5b1c0046a3ada2fa173941ef6c360f937a4e9e825490bf6b694e177cfc593c3ce43d48763812efe
-
SSDEEP
6144:I9inN+UqL02g1gH2H4gCW3e0dZfFgCZTdsmnElM2/uLYwG2iIMRD51TK7HV/Smhc:0ipHgWYO1dTdxGmnO9/1Ft2SGjFW
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 203faeab73cd2cb1e4e588bc0628b8b0_JaffaCakes118
Files
-
203faeab73cd2cb1e4e588bc0628b8b0_JaffaCakes118.exe windows:4 windows x86 arch:x86
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Sections
Size: 86KB - Virtual size: 200KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 5KB - Virtual size: 12KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 17KB - Virtual size: 660KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 3KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: - Virtual size: 16KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.SIZ Size: 266KB - Virtual size: 268KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.adata Size: - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE