General

  • Target

    201b3ddbaeaa3cc5f7480d8fe72fc567_JaffaCakes118

  • Size

    7.3MB

  • MD5

    201b3ddbaeaa3cc5f7480d8fe72fc567

  • SHA1

    18fb6b4aa14e9594a5722778fbd77fc8f7a929f9

  • SHA256

    95a8e22f4586b962c8bbe268f28b9561ecfafc06bee75f3571ced253d66d5531

  • SHA512

    17e4d6fff52a6bec3de4912a7fa616361ea7a758bf2a080505865fb1743c32c50bb69e3f6588b1f4dbaf4f32de855bbcd0766342b887d0acefc0b8f9980bd24b

  • SSDEEP

    196608:McQNXCaslUWm2z+msNMl1ADcUjOIEs3jHvau5B38MVCcr9:VSslOJ3cgTjPau5/C+9

Score
7/10
upx

Malware Config

Signatures

  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 18 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • 201b3ddbaeaa3cc5f7480d8fe72fc567_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    099c0646ea7282d232219f8807883be0


    Headers

    Imports

    Sections

  • $PLUGINSDIR/InstallOptions.dll
    .dll windows:4 windows x86 arch:x86

    b1cd0d78f652ce5fc63f0879371af012


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/LangDLL.dll
    .dll windows:4 windows x86 arch:x86

    9b6b6a7858e17fb0b17e1c1428330343


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/NSISdl.dll
    .dll windows:4 windows x86 arch:x86

    9cce555dd3ff1b6c7dc92d64c794c51a


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    2017f2acbdaa42ab3e4adeb8b4c37e7b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/ioSpecial.ini
  • $PLUGINSDIR/modern-wizard.bmp
  • CCleaner.exe
    .exe windows:4 windows x86 arch:x86

    61c5d0f873f720dd1c7be1d3202eac71


    Code Sign

    Headers

    Imports

    Sections

  • Microsoft.VC80.CRT.manifest
    .xml
  • Microsoft.VC90.CRT.manifest
  • Microsoft.mshtml.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • cafw.exe
    .exe windows:5 windows x86 arch:x86

    4710e694cbc904bbde58b1960e1a3f6b


    Headers

    Imports

    Sections

  • cafw.exe.config
    .xml
  • cladgenius.chm
    .chm
  • decaptcher.dll
    .dll windows:4 windows x86 arch:x86

    ea8805c61d622df6eaee4161fb6b710f


    Headers

    Imports

    Exports

    Sections

  • eula.txt
  • fbclient.dll
    .dll windows:4 windows x86 arch:x86

    3e57f561fc826c2ff17b3af7fd3613f9


    Headers

    Imports

    Exports

    Sections

  • firebird.conf
  • firebird.msg
  • holfix.exe
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • ibprovider.dll
    .dll regsvr32 windows:5 windows x86 arch:x86

    bbbb1f48f3cf8299b104330fe60ca1f7


    Headers

    Imports

    Exports

    Sections

  • icudt30.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Exports

    Sections

  • icuin30.dll
    .dll windows:4 windows x86 arch:x86

    9beb482b2a2508a095c34c1fa62d842c


    Headers

    Imports

    Exports

    Sections

  • icuuc30.dll
    .dll windows:4 windows x86 arch:x86

    46b127392715a22298552eac440752c6


    Headers

    Imports

    Exports

    Sections

  • msvcp80.dll
    .dll windows:4 windows x86 arch:x86

    9fb682fe34f5d965faf4cf424fa6c000


    Headers

    Imports

    Exports

    Sections

  • msvcp90.dll
    .dll windows:5 windows x86 arch:x86

    2dec2d42421b088bfcddeba53b046464


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • msvcr80.dll
    .dll windows:4 windows x86 arch:x86

    8eb98c77a1ada89df5027bd5bf01c2f6


    Headers

    Imports

    Exports

    Sections

  • msvcr90.dll
    .dll windows:5 windows x86 arch:x86

    0453db624ecaef7c4f3da938cd1d0fc5


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • wm_hooks.dll
    .dll windows:5 windows x86 arch:x86

    41bb4d885b3f33a71b60c014092700d0


    Headers

    Imports

    Exports

    Sections