Analysis
-
max time kernel
149s -
max time network
150s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
06-06-2024 15:40
Behavioral task
behavioral1
Sample
1712-0-0x0000000000080000-0x000000000008D000-memory.exe
Resource
win7-20240508-en
windows7-x64
0 signatures
150 seconds
Behavioral task
behavioral2
Sample
1712-0-0x0000000000080000-0x000000000008D000-memory.exe
Resource
win10v2004-20240508-en
windows10-2004-x64
1 signatures
150 seconds
General
-
Target
1712-0-0x0000000000080000-0x000000000008D000-memory.exe
-
Size
52KB
-
MD5
3613b0e67edf6a6bf48a9311ada3c940
-
SHA1
a0973aec11b650bfa6cf03dea513a8b105092cbc
-
SHA256
7fffca501d8cb44b9a508e49169ec61afac161fd3a6d143ca0f2ca23021df49e
-
SHA512
25dd93193dd0964134ef6c2a0b1c4cd498faf2437afa1684e665552a0cf9bd487e36b3f7bafa9b529de5e79bced90016683eed80df1ee4d85bbf7ed9a51a3ca7
-
SSDEEP
768:xTOI/KasXcap4GsbNftF/Nll1h9uWVxolQ+p1t9FzZR1ob7FnwYbvKBQO:xN/KrXcaebNftX1h9JolD9FtAS/QO
Score
3/10
Malware Config
Signatures
-
Program crash 1 IoCs
Processes:
WerFault.exepid pid_target process target process 4776 940 WerFault.exe 1712-0-0x0000000000080000-0x000000000008D000-memory.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\1712-0-0x0000000000080000-0x000000000008D000-memory.exe"C:\Users\Admin\AppData\Local\Temp\1712-0-0x0000000000080000-0x000000000008D000-memory.exe"1⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 940 -s 2162⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 940 -ip 9401⤵