Analysis

  • max time kernel
    150s
  • max time network
    150s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240426-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240426-enlocale:en-usos:windows10-2004-x64system
  • submitted
    02-06-2024 13:03

General

  • Target

    uninst.exe

  • Size

    67KB

  • MD5

    0a24574cd9f484a9a72056fb187758d8

  • SHA1

    65502d1fdac883d33eff6f335eab9ef87ac8e9eb

  • SHA256

    7947b56a572bb9de99145af441ceb0f58000ca1048e6e3cdf7db397add40794d

  • SHA512

    12a4243d5f6672d80d22e767fa3b8b1aa73ab1afef4ce4ec0524e4555ca49f04c593df6240b7e7ef7ef526ca7ab38c62e43fc1c30bb02e82d6b9b1b26eacea56

  • SSDEEP

    1536:AU+dcy3fxBk9UmZHs/hcQgdLeAyNxdnw+HMKUKB5TiN5h:ANzPHk9MpcQceAcwWMKU6k

Score
7/10

Malware Config

Signatures

  • Executes dropped EXE 1 IoCs
  • Loads dropped DLL 3 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • NSIS installer 2 IoCs
  • Suspicious use of WriteProcessMemory 3 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\uninst.exe
    "C:\Users\Admin\AppData\Local\Temp\uninst.exe"
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:4440
    • C:\Users\Admin\AppData\Local\Temp\~nsuA.tmp\Un_A.exe
      "C:\Users\Admin\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=C:\Users\Admin\AppData\Local\Temp\
      2⤵
      • Executes dropped EXE
      • Loads dropped DLL
      PID:1708

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Local\Temp\nse3896.tmp\System.dll
    Filesize

    11KB

    MD5

    55a26d7800446f1373056064c64c3ce8

    SHA1

    80256857e9a0a9c8897923b717f3435295a76002

    SHA256

    904fd5481d72f4e03b01a455f848dedd095d0fb17e33608e0d849f5196fb6ff8

    SHA512

    04b8ab7a85c26f188c0a06f524488d6f2ac2884bf107c860c82e94ae12c3859f825133d78338fd2b594dfc48f7dc9888ae76fee786c6252a5c77c88755128a5b

  • C:\Users\Admin\AppData\Local\Temp\nse3896.tmp\nsDialogs.dll
    Filesize

    9KB

    MD5

    ee449b0adce56fbfa433b0239f3f81be

    SHA1

    ec1e4f9815ea592a3f19b1fe473329b8ddfa201c

    SHA256

    c1cc3aa4326e83a73a778dee0cf9afcc03a6bafb0a32cea791a27eb9c2288985

    SHA512

    22fb25bc7628946213e6e970a865d3fbd50d12ce559c37d6848a82c28fa6be09fedffc3b87d5aea8dcfe8dfc4e0f129d9f02e32dae764b8e6a08332b42386686

  • C:\Users\Admin\AppData\Local\Temp\~nsuA.tmp\Un_A.exe
    Filesize

    67KB

    MD5

    0a24574cd9f484a9a72056fb187758d8

    SHA1

    65502d1fdac883d33eff6f335eab9ef87ac8e9eb

    SHA256

    7947b56a572bb9de99145af441ceb0f58000ca1048e6e3cdf7db397add40794d

    SHA512

    12a4243d5f6672d80d22e767fa3b8b1aa73ab1afef4ce4ec0524e4555ca49f04c593df6240b7e7ef7ef526ca7ab38c62e43fc1c30bb02e82d6b9b1b26eacea56