Analysis
-
max time kernel
118s -
max time network
119s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
31-05-2024 09:39
Behavioral task
behavioral1
Sample
2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe
Resource
win7-20240508-en
2 signatures
150 seconds
Behavioral task
behavioral2
Sample
2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe
Resource
win10v2004-20240508-en
1 signatures
150 seconds
General
-
Target
2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe
-
Size
1.1MB
-
MD5
5e046e25428f1cb625049462a13b8130
-
SHA1
90b80e44d1e065994e7a51677be756305be781bf
-
SHA256
825dfbf24f4cc2a54c6c1cdcb30e79df24332f485401ad55663a5c643400bbd9
-
SHA512
45a01c909c72f8bc94702d20b4fb917dac7d030ab6229ef723158af5364ac1a56a84d55499e479cfac830bd87fb580929b18bbce24cec4f1dd15b561b3490dd0
-
SSDEEP
24576:ZBUIKn/vwOXGUXAjCymYZiVtElVIBT2roqnTSSxWeT/XRPOO8SiHUq7:F0dwAYZt6C31WeTPRPOhSGUq7
Score
3/10
Malware Config
Signatures
-
Program crash 1 IoCs
Processes:
WerFault.exepid pid_target process target process 1464 1712 WerFault.exe 2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exedescription pid process target process PID 1712 wrote to memory of 1464 1712 2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe WerFault.exe PID 1712 wrote to memory of 1464 1712 2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe WerFault.exe PID 1712 wrote to memory of 1464 1712 2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe WerFault.exe PID 1712 wrote to memory of 1464 1712 2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe WerFault.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe"C:\Users\Admin\AppData\Local\Temp\2024-05-31_5e046e25428f1cb625049462a13b8130_stop.exe"1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 1712 -s 1922⤵
- Program crash