Analysis

  • max time kernel
    145s
  • max time network
    152s
  • platform
    windows11-21h2_x64
  • resource
    win11-20240508-en
  • resource tags

    arch:x64arch:x86image:win11-20240508-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    15-06-2024 13:36

General

  • Target

    pcwum/AppxSip.dll

  • Size

    268KB

  • MD5

    577dbb84e03e995d507840258c52913f

  • SHA1

    cb1d426d26a3e966d29a6a28f94ed5273c21d759

  • SHA256

    c8ed0608c107745d56fcdf34cac855602c65dc1a612c173f4057cbd30fbf2058

  • SHA512

    90263941720d4498cfe588ecc7c713f04ce2431722b918859c555041be1823ace5163306c3e273e92fde0d472b3bb494acc37b26982a269116b64ed13aa396cf

  • SSDEEP

    6144:cTXUiOy2C35UKI+EqJNLo/AKjJIcLIT9mAD:cTkFy2aI+FLSHjJIcsR

Score
8/10

Malware Config

Signatures

  • Manipulates Digital Signatures 1 TTPs 60 IoCs

    Attackers can apply techniques such as changing the registry keys of authenticode & Cryptography to obtain their binary as valid.

Processes

  • C:\Windows\system32\regsvr32.exe
    regsvr32 /s C:\Users\Admin\AppData\Local\Temp\pcwum\AppxSip.dll
    1⤵
    • Manipulates Digital Signatures
    PID:4404

Network

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

SIP and Trust Provider Hijacking

1
T1553.003

Replay Monitor

Loading Replay Monitor...

Downloads