General
-
Target
280c4d22fd6c0fb6bbcd748f0b3df79e_JaffaCakes118
-
Size
114KB
-
Sample
240706-lex3pawglb
-
MD5
280c4d22fd6c0fb6bbcd748f0b3df79e
-
SHA1
a5afaa1ff6115117e7ead34493acbfcaf6757c26
-
SHA256
e13feab4f1fc2ec98668e75f7080e539b0006008d83eafa64e129b2b2ec997f1
-
SHA512
308460e492deb756de30578f841a02d0806ab5141dc6a32a0c1c5b05ce7c4bcb4a432438d97651a2b6e9a3f6fca41f6987de0238d86aa1c9dc22f601c23b763a
-
SSDEEP
3072:/XAtWYKBlVJnGseFwyb5Mwlg66moVqxOsd2gW9:fAoYKXVJL8wyb2E1Osd2g
Static task
static1
Behavioral task
behavioral1
Sample
280c4d22fd6c0fb6bbcd748f0b3df79e_JaffaCakes118.exe
Resource
win7-20240221-en
Malware Config
Extracted
pony
http://etsiunjour.fr:81/pony/gate.php
http://69.194.194.238/pony/gate.php
-
payload_url
http://www.nipbr.com/Macs.exe
http://propasmanagement.com/qTNc.exe
http://ajc.com.pk/LnL.exe
Targets
-
-
Target
280c4d22fd6c0fb6bbcd748f0b3df79e_JaffaCakes118
-
Size
114KB
-
MD5
280c4d22fd6c0fb6bbcd748f0b3df79e
-
SHA1
a5afaa1ff6115117e7ead34493acbfcaf6757c26
-
SHA256
e13feab4f1fc2ec98668e75f7080e539b0006008d83eafa64e129b2b2ec997f1
-
SHA512
308460e492deb756de30578f841a02d0806ab5141dc6a32a0c1c5b05ce7c4bcb4a432438d97651a2b6e9a3f6fca41f6987de0238d86aa1c9dc22f601c23b763a
-
SSDEEP
3072:/XAtWYKBlVJnGseFwyb5Mwlg66moVqxOsd2gW9:fAoYKXVJL8wyb2E1Osd2g
-
Accesses Microsoft Outlook accounts
-
Accesses Microsoft Outlook profiles
-
Checks installed software on the system
Looks up Uninstall key entries in the registry to enumerate software on the system.
-
Suspicious use of SetThreadContext
-