Analysis

  • max time kernel
    149s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    02-06-2024 03:36

General

  • Target

    dd55fb05f6fd9e069265a665c8e79f8eec27b50c6f9ae793bb28105a55f81a62.exe

  • Size

    4KB

  • MD5

    3ffa2b51c80e07ae56bcd4820aac371f

  • SHA1

    c9eb3b825a5c267a388c120ad57fd86446243813

  • SHA256

    dd55fb05f6fd9e069265a665c8e79f8eec27b50c6f9ae793bb28105a55f81a62

  • SHA512

    1e706e50c306d90da6071bd5e9ac1b3cf1470a7eaf5bb1382c355dde8a25d1101a751867ac14b92591c5f827ccd2c560830d23f252d6b8a2ff72d9d07a982d79

  • SSDEEP

    96:Z0v4mUWKh9ctgC1RMJOnKymV44ShylyzUA3:9mUWKs/JnKfzShyLA3

Score
10/10

Malware Config

Signatures

  • Upatre

    Upatre is a generic malware downloader.

  • Executes dropped EXE 1 IoCs
  • Loads dropped DLL 2 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Suspicious use of WriteProcessMemory 4 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\dd55fb05f6fd9e069265a665c8e79f8eec27b50c6f9ae793bb28105a55f81a62.exe
    "C:\Users\Admin\AppData\Local\Temp\dd55fb05f6fd9e069265a665c8e79f8eec27b50c6f9ae793bb28105a55f81a62.exe"
    1⤵
    • Loads dropped DLL
    • Suspicious use of WriteProcessMemory
    PID:2936
    • C:\Users\Admin\AppData\Local\Temp\szgfw.exe
      "C:\Users\Admin\AppData\Local\Temp\szgfw.exe"
      2⤵
      • Executes dropped EXE
      PID:2012

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • \Users\Admin\AppData\Local\Temp\szgfw.exe
    Filesize

    4KB

    MD5

    ce1c0ef78e285de57e22ec87d9d566b0

    SHA1

    4f64d9457b2ceff78952c7833ecdcf3b4a7bc857

    SHA256

    6d1477cbdaa568f9b0d8e514b2db49e04076d454db4eab5b0f7911bcb02c7c84

    SHA512

    afb309df81e58ccf75de5c10f75fd37e8ded726fe28c43fc1432e1b74ab837281f353511c596ecf89dfef273625008972251a34d7d08490b51feb4403ad4ab26