Static task
static1
Behavioral task
behavioral1
Sample
253a01a3885449b469b5d48701c1f1b0_JaffaCakes118.exe
Resource
win7-20240419-en
General
-
Target
253a01a3885449b469b5d48701c1f1b0_JaffaCakes118
-
Size
278KB
-
MD5
253a01a3885449b469b5d48701c1f1b0
-
SHA1
c152218d2ed37052b8e5808c45246bbb0dd7f8cd
-
SHA256
54eead45e2f5c5d49a65e9b6d2ccb79dad19acd6952713dddbdb1deedac57936
-
SHA512
91f30a2ccf7f2ed339c7531f130058af77629ccf538da88c819b5994cfdc13ff343d4cd52bc676436de201ad2252e7db5f8a3692b50fee146c72681b3cc8f089
-
SSDEEP
6144:rwmpb9Zz43C+A9cvUEEpXYMSkDZcxOqcDIrM:rwml9t43CTAM1uZA
Malware Config
Signatures
-
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 253a01a3885449b469b5d48701c1f1b0_JaffaCakes118
Files
-
253a01a3885449b469b5d48701c1f1b0_JaffaCakes118.exe windows:4 windows x86 arch:x86
208e0e9800f506382bac5fba9b9b7414
Headers
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
setupapi
CM_Get_Child
SetupDiGetDeviceRegistryPropertyW
CMP_WaitNoPendingInstallEvents
CM_Get_DevNode_Status
kernel32
lstrlenA
SetFilePointer
VirtualProtect
LeaveCriticalSection
GetStringTypeW
AddAtomA
LoadLibraryA
GetProcAddress
LCMapStringA
FreeLibrary
GetOEMCP
GetEnvironmentStringsW
GetLastError
FreeEnvironmentStringsA
WriteFile
GetModuleHandleA
GetCPInfo
FreeEnvironmentStringsW
lstrcmpA
lstrcpynA
GetFullPathNameA
lstrcpyA
IsBadReadPtr
GetStartupInfoA
FindFirstFileA
GetFileAttributesA
EnumResourceNamesW
lstrcatA
CloseHandle
LCMapStringW
Sleep
GetStringTypeA
ReadFile
InitializeCriticalSection
GetCurrentThreadId
WideCharToMultiByte
IsBadCodePtr
SetDllDirectoryW
EnterCriticalSection
SetStdHandle
SetUnhandledExceptionFilter
GetDiskFreeSpaceA
MulDiv
DeleteCriticalSection
GetTickCount
UnhandledExceptionFilter
CreateFileA
MultiByteToWideChar
GetThreadLocale
lstrcmpiA
GetEnvironmentStrings
FlushFileBuffers
RaiseException
Sections
.text Size: 140KB - Virtual size: 276KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 2KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 134KB - Virtual size: 134KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 512B - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ