Analysis

  • max time kernel
    129s
  • max time network
    137s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    10-04-2024 12:21

General

  • Target

    8758196b4266ca7809e54c84ff6767784cb105fce247ad3459a15bb8ef9032c8.dll

  • Size

    1.2MB

  • MD5

    2e308cddc0ce7d37fd974d087d75386d

  • SHA1

    673898f79e973abb733d6200c011b330f6355de1

  • SHA256

    8758196b4266ca7809e54c84ff6767784cb105fce247ad3459a15bb8ef9032c8

  • SHA512

    9198e727b088f709a7ccbc1f8d86436b448aa80f346b247eaa075f65e2f23bc640846890cd3d0bf270230e2ccba8c535a7ae66d34e7edfe3f1b683cb38f3b710

  • SSDEEP

    12288:mvo5tl6YdMeVEjsGUGpBIMgcoOQgMIW6LAUoUGA8l2HDQr1NTkJMW:mvongYWvjsoDIMgcBxMIW6VHMUMW

Malware Config

Signatures

  • Bazar Loader

    Detected loader normally used to deploy BazarBackdoor malware.

  • Bazar/Team9 Loader payload 2 IoCs

Processes

  • C:\Windows\system32\regsvr32.exe
    regsvr32 /s C:\Users\Admin\AppData\Local\Temp\8758196b4266ca7809e54c84ff6767784cb105fce247ad3459a15bb8ef9032c8.dll
    1⤵
      PID:2660

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2660-0-0x00000000001B0000-0x00000000001D4000-memory.dmp
      Filesize

      144KB

    • memory/2660-1-0x00000000001B0000-0x00000000001D4000-memory.dmp
      Filesize

      144KB