General

  • Target

    25db368cc7c0308d014ce0397bd7adac_JaffaCakes118

  • Size

    3.9MB

  • MD5

    25db368cc7c0308d014ce0397bd7adac

  • SHA1

    e7f05494b314747a5ddd0bb41c73289623235ba4

  • SHA256

    d2623ed0469b4a7a8f9371cb91bad7bb803564bdda76fdcc5972905edb12f8b9

  • SHA512

    92758b707791cf297cc0b311d38e503095e1b7769a385202c527c4242d2e2f7561d1af9d5d13f0fd6c9d739aae131d58f3eca3dd12c515d0e9a305ea6de4a8f7

  • SSDEEP

    98304:qiO3DcIFRtNXWRaslUWKj1Bl20I+QRFKX9Mle:McQNXCaslUWm2z+msNMle

Score
7/10
upx

Malware Config

Signatures

  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 17 IoCs

    Checks for missing Authenticode signature.

  • NSIS installer 2 IoCs

Files

  • 25db368cc7c0308d014ce0397bd7adac_JaffaCakes118
    .exe windows:4 windows x86 arch:x86

    099c0646ea7282d232219f8807883be0


    Headers

    Imports

    Sections

  • $PLUGINSDIR/InstallOptions.dll
    .dll windows:4 windows x86 arch:x86

    b1cd0d78f652ce5fc63f0879371af012


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/LangDLL.dll
    .dll windows:4 windows x86 arch:x86

    9b6b6a7858e17fb0b17e1c1428330343


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/NSISdl.dll
    .dll windows:4 windows x86 arch:x86

    9cce555dd3ff1b6c7dc92d64c794c51a


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/System.dll
    .dll windows:4 windows x86 arch:x86

    2017f2acbdaa42ab3e4adeb8b4c37e7b


    Headers

    Imports

    Exports

    Sections

  • $PLUGINSDIR/ioSpecial.ini
  • $PLUGINSDIR/modern-wizard.bmp
  • CCleaner.exe
    .exe windows:4 windows x86 arch:x86

    61c5d0f873f720dd1c7be1d3202eac71


    Code Sign

    Headers

    Imports

    Sections

  • Microsoft.VC80.CRT.manifest
    .xml
  • Microsoft.VC90.CRT.manifest
  • Microsoft.mshtml.dll
    .dll windows:4 windows x86 arch:x86

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • cafw.exe.config
    .xml
  • decaptcher.dll
    .dll windows:4 windows x86 arch:x86

    ea8805c61d622df6eaee4161fb6b710f


    Headers

    Imports

    Exports

    Sections

  • eula.txt
  • fbclient.dll
    .dll windows:4 windows x86 arch:x86

    3e57f561fc826c2ff17b3af7fd3613f9


    Headers

    Imports

    Exports

    Sections

  • firebird.conf
  • firebird.msg
  • holfix.exe
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • out.upx
    .exe windows:5 windows x86 arch:x86


    Headers

    Sections

  • ibprovider.dll
    .dll windows:5 windows x86 arch:x86


    Headers

    Sections

  • icudt30.dll
    .dll windows:4 windows x86 arch:x86


    Headers

    Exports

    Sections

  • icuin30.dll
    .dll windows:4 windows x86 arch:x86

    9beb482b2a2508a095c34c1fa62d842c


    Headers

    Imports

    Exports

    Sections

  • icuuc30.dll
    .dll windows:4 windows x86 arch:x86

    46b127392715a22298552eac440752c6


    Headers

    Imports

    Exports

    Sections

  • msvcp80.dll
    .dll windows:4 windows x86 arch:x86

    9fb682fe34f5d965faf4cf424fa6c000


    Headers

    Imports

    Exports

    Sections

  • msvcp90.dll
    .dll windows:5 windows x86 arch:x86

    2dec2d42421b088bfcddeba53b046464


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • msvcr80.dll
    .dll windows:4 windows x86 arch:x86

    8eb98c77a1ada89df5027bd5bf01c2f6


    Headers

    Imports

    Exports

    Sections

  • msvcr90.dll
    .dll windows:5 windows x86 arch:x86

    0453db624ecaef7c4f3da938cd1d0fc5


    Code Sign

    Headers

    Imports

    Exports

    Sections

  • wm_hooks.dll
    .dll windows:5 windows x86 arch:x86

    41bb4d885b3f33a71b60c014092700d0


    Headers

    Imports

    Exports

    Sections