General
-
Target
JaffaCakes118_0657402fde6812b9c78f7be0f59808e0
-
Size
809KB
-
Sample
250517-1ylakahm5t
-
MD5
0657402fde6812b9c78f7be0f59808e0
-
SHA1
c6eb512b740b10d7ac51e67355397460cbfbe82b
-
SHA256
4be940d68dba5ce62903b18ea0a015c67c2f6a91c33d3d70020c8395533c74bb
-
SHA512
149a2795106a360f2f339d3f1d1f95f18e26275a1772bd82b0017b73cd2f8cbbe2c379eee8ffd6ab893e5bddc2e85744865eb23874537d3f6ee6005f8f138cb0
-
SSDEEP
24576:4VdUxJkUMBGceP2Dr87SARn7NNaDjmQ0Xs:7/7sW2P+xRnhNOfs
Static task
static1
Behavioral task
behavioral1
Sample
JaffaCakes118_0657402fde6812b9c78f7be0f59808e0.exe
Resource
win10v2004-20250502-en
Malware Config
Targets
-
-
Target
JaffaCakes118_0657402fde6812b9c78f7be0f59808e0
-
Size
809KB
-
MD5
0657402fde6812b9c78f7be0f59808e0
-
SHA1
c6eb512b740b10d7ac51e67355397460cbfbe82b
-
SHA256
4be940d68dba5ce62903b18ea0a015c67c2f6a91c33d3d70020c8395533c74bb
-
SHA512
149a2795106a360f2f339d3f1d1f95f18e26275a1772bd82b0017b73cd2f8cbbe2c379eee8ffd6ab893e5bddc2e85744865eb23874537d3f6ee6005f8f138cb0
-
SSDEEP
24576:4VdUxJkUMBGceP2Dr87SARn7NNaDjmQ0Xs:7/7sW2P+xRnhNOfs
-
Hawkeye family
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Uses the VBS compiler for execution
-
Accesses Microsoft Outlook accounts
-
Adds Run key to start application
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-
Suspicious use of SetThreadContext
-