Analysis
-
max time kernel
147s -
max time network
150s -
platform
windows10-2004_x64 -
resource
win10v2004-20240426-en -
resource tags
arch:x64arch:x86image:win10v2004-20240426-enlocale:en-usos:windows10-2004-x64system -
submitted
01-06-2024 07:54
Static task
static1
Behavioral task
behavioral1
Sample
Agreement CA8292019D4501.vbs
Resource
win7-20231129-en
General
-
Target
Agreement CA8292019D4501.vbs
-
Size
795KB
-
MD5
c877524243319a178f38671c3a33eaaf
-
SHA1
f5da68a8d5ef7b3fab82e19a8b4c1118c9a109bd
-
SHA256
9e65f5319d3c64a0db0a6c39b4d7be40f98f607c3fb3e5c50d7acc337d2ed4bc
-
SHA512
1f84f9ce971883ac44c41fbfd8bc6e5dd8c987dde594844c0b46613fcc4b74583fefb2d5ff09d7510993bd3502830dc8d9b34ad33a6677fa6a2200cabdb0ee1c
-
SSDEEP
24576:YmKQH76xpqoeAehhxyWgePLlN4dLQwClvxya8Hc6vP3v3EfvPWFkv6j:xexpqcehhxyXwLl+9
Malware Config
Extracted
dridex
89.32.150.160:3389
152.46.8.148:884
69.55.238.203:3389
Signatures
-
Processes:
resource yara_rule behavioral2/memory/468-4-0x0000000000930000-0x0000000000972000-memory.dmp dridex_ldr behavioral2/memory/468-7-0x0000000000930000-0x0000000000972000-memory.dmp dridex_ldr -
Executes dropped EXE 1 IoCs
Processes:
KqdQZMj.exepid process 468 KqdQZMj.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\KqdQZMj.exeFilesize
260KB
MD5215b7fea557c856169847d694b94beab
SHA1a35185736906211688949cf29acc05722bd2a31a
SHA256cf97f6cc84108eb1c788902abf54f91d1c6398bbaa6df198121031740fb74c8b
SHA5120a7622bc93feb184bf458cef4613f0cddd8d43c7dd415a5599332d42dd9313b14910bf7e08c7f8a1a0e0180dcbfe34bb55a7fd90b773a94f997d47269dbb697c
-
memory/468-4-0x0000000000930000-0x0000000000972000-memory.dmpFilesize
264KB
-
memory/468-6-0x00000000011F0000-0x00000000011F6000-memory.dmpFilesize
24KB
-
memory/468-7-0x0000000000930000-0x0000000000972000-memory.dmpFilesize
264KB