Behavioral task
behavioral1
Sample
7076a4830f2294b3f5ed5f695a6809bf30d2532fe768a579e8a13d6ed90d957a.exe
Resource
win7-20240611-en
General
-
Target
7076a4830f2294b3f5ed5f695a6809bf30d2532fe768a579e8a13d6ed90d957a
-
Size
917KB
-
MD5
b89e484260d55420abd2837adf1fbb5e
-
SHA1
25f5e70c144f9bf3383892104c82f7382f824424
-
SHA256
7076a4830f2294b3f5ed5f695a6809bf30d2532fe768a579e8a13d6ed90d957a
-
SHA512
983f3116111a999f316d494a7db538e6f9a2f2f2fa811fb08e28628a435876e7c52577f2998f3e700599d128c95f4afa189e117f3cda7003694de65a423c2952
-
SSDEEP
24576:+554MROxnFD3cw8XlrrcI0AilFEvxHPhCoog:+QMiJArrcI0AilFEvxHP
Malware Config
Extracted
orcus
selected-prove.gl.at.ply.gg:23398
607dffe61a7d4757a14c10330fc5e802
-
autostart_method
TaskScheduler
-
enable_keylogger
false
-
install_path
%programfiles%\Microsoft\Edge\Application\msupdate.exe
-
reconnect_delay
10000
-
registry_keyname
Microsoft Edgde Updater
-
taskscheduler_taskname
Microsoft Edge Runtime
-
watchdog_path
Temp\ALKI@#PI!J)PRa)(r.exe
Signatures
-
Orcurs Rat Executable 1 IoCs
Processes:
resource yara_rule sample orcus -
Orcus family
-
Orcus main payload 1 IoCs
Processes:
resource yara_rule sample family_orcus -
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource 7076a4830f2294b3f5ed5f695a6809bf30d2532fe768a579e8a13d6ed90d957a
Files
-
7076a4830f2294b3f5ed5f695a6809bf30d2532fe768a579e8a13d6ed90d957a.exe windows:4 windows x86 arch:x86
f34d5f2d4577ed6d9ceec516c1f5a744
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
mscoree
_CorExeMain
Sections
.text Size: 912KB - Virtual size: 911KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 4KB - Virtual size: 4KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ