Analysis

  • max time kernel
    423s
  • max time network
    447s
  • platform
    windows11-21h2_x64
  • resource
    win11-20231215-en
  • resource tags

    arch:x64arch:x86image:win11-20231215-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    20-12-2023 01:43

General

  • Target

    a925fc1289573f01bb86482e38340f0fe431269aa7500d776713c71091c49142.exe

  • Size

    101KB

  • MD5

    9618523352c980cc2fdb2533e16d7b08

  • SHA1

    c518747935e16bfa8b7e8bedb38fc37d7afa386d

  • SHA256

    a925fc1289573f01bb86482e38340f0fe431269aa7500d776713c71091c49142

  • SHA512

    cb68601b5f3a808b6a8a2f90b386293ba21b13ac15981ea20abd03324f2d6cb1922b2425d5fa4b66a0ab5603843dc73ee14b62c1f8206bd58569a0441a097551

  • SSDEEP

    1536:8uxpMqqU+NV2I8ShQEBpFiAVMS4O8gOkfDiGyIUt39p3VbWL8:8iMqqDLn8SuUKIMS42fDiGyIW9dVo8

Score
7/10

Malware Config

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\a925fc1289573f01bb86482e38340f0fe431269aa7500d776713c71091c49142.exe
    "C:\Users\Admin\AppData\Local\Temp\a925fc1289573f01bb86482e38340f0fe431269aa7500d776713c71091c49142.exe"
    1⤵
      PID:4524

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Credential Access

    Unsecured Credentials

    1
    T1552

    Credentials In Files

    1
    T1552.001

    Collection

    Data from Local System

    1
    T1005

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/4524-0-0x00000000005A0000-0x00000000005C0000-memory.dmp
      Filesize

      128KB

    • memory/4524-1-0x00000000751C0000-0x0000000075971000-memory.dmp
      Filesize

      7.7MB

    • memory/4524-3-0x00000000055E0000-0x0000000005646000-memory.dmp
      Filesize

      408KB

    • memory/4524-2-0x0000000002830000-0x0000000002840000-memory.dmp
      Filesize

      64KB

    • memory/4524-9-0x00000000057F0000-0x000000000588C000-memory.dmp
      Filesize

      624KB

    • memory/4524-13-0x00000000751C0000-0x0000000075971000-memory.dmp
      Filesize

      7.7MB

    • memory/4524-14-0x0000000002830000-0x0000000002840000-memory.dmp
      Filesize

      64KB