Overview
overview
10Static
static
3Loader/Ant...sabler
windows10-1703-x64
1Loader/Gam...Inject
windows10-1703-x64
1Loader/Gam...meMenu
windows10-1703-x64
1Loader/Gam...Status
windows10-1703-x64
1Loader/GameDetect
windows10-1703-x64
1Loader/Launcher.dll
windows10-1703-x64
1Loader/Loader.exe
windows10-1703-x64
10Loader/Upd...pdater
windows10-1703-x64
1Loader/Upd...eb.xml
windows10-1703-x64
1Loader/config
windows10-1703-x64
1Loader/mainf.dll
windows10-1703-x64
1Loader/mco...ig.xml
windows10-1703-x64
1Analysis
-
max time kernel
134s -
max time network
142s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
15-06-2024 19:50
Static task
static1
Behavioral task
behavioral1
Sample
Loader/AntiCheatDisabler
Resource
win10-20240404-en
Behavioral task
behavioral2
Sample
Loader/GameCheck/GameInject
Resource
win10-20240611-en
Behavioral task
behavioral3
Sample
Loader/GameCheck/GameMenu
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
Loader/GameCheck/GameStatus
Resource
win10-20240404-en
Behavioral task
behavioral5
Sample
Loader/GameDetect
Resource
win10-20240404-en
Behavioral task
behavioral6
Sample
Loader/Launcher.dll
Resource
win10-20240404-en
Behavioral task
behavioral7
Sample
Loader/Loader.exe
Resource
win10-20240404-en
Behavioral task
behavioral8
Sample
Loader/Updater/Updater
Resource
win10-20240404-en
Behavioral task
behavioral9
Sample
Loader/Updater/web.xml
Resource
win10-20240404-en
Behavioral task
behavioral10
Sample
Loader/config
Resource
win10-20240404-en
Behavioral task
behavioral11
Sample
Loader/mainf.dll
Resource
win10-20240611-en
Behavioral task
behavioral12
Sample
Loader/mconfig/config.xml
Resource
win10-20240404-en
General
-
Target
Loader/Updater/web.xml
-
Size
18KB
-
MD5
b127480ee9f0b8dab6a3f73ad79dd332
-
SHA1
7d776d730cbd253564713f36573dd8366782788c
-
SHA256
f1a6416eeedd9d040387fd85dcf7d6e074b6644c6829d08be220ff9fc32efb31
-
SHA512
00ddca43ad38127cf71477810c46617fc2ccdc33f197e26ba761151107eff701fec2caa51e43575fb5b4fbc11f640f525ba70b6b3e97811cecabc63773492401
-
SSDEEP
384:lJJuAr8F1mJ1ayCk5+HK5YaW41DBWTwahst/tlLvSqwwU4FVXaS7L3nHIXYFXc//:jbpJX91Xbi
Malware Config
Signatures
-
Processes:
IEXPLORE.EXEiexplore.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\GPU IEXPLORE.EXE Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\DomainSuggestion\FileNames\ iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$vBulletin 3 iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\DecayDateQueue = 01000000d08c9ddf0115d1118c7a00c04fc297eb01000000c517910592b48541be24303fa89e939b000000000200000000001066000000010000200000007082b2e5722d4b06f4b8bac339cc0e3cd1d8e195656bc7dc01f201f95ada39c9000000000e8000000002000020000000f0a8138fabf38e56e12669dc1d710a266ab0d02db6bb93b07b50cd1dc0bf7b5420000000320dcc5ce74fe424f3dcaccd21156eb52ad5d9bd44c51182b3852548b0ae01ba400000009420fadaf3d85e5dd20ffeac7feae4c6766e746e48f9e7fe872cbf6f45d846e1a61016a2e66eee7152aaf3c52a91a1c5bc2d04f2674e87cdcfe6f6e8c2a36a54 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastTTLHighDateTime = "50" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NTPFirstRun = "1" iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\DomainSuggestion\FileNames\en-US = "en-US.1" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$Discuz! iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$MediaWiki iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\NextUpdateDate = "425294605" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags = "0" iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version = "WS not running" iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\DomainSuggestion\FileNames iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastCheckForUpdateHighDateTime = "31113053" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastCheckForUpdateHighDateTime = "31113053" IEXPLORE.EXE Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$WordPress iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version = "WS not running" IEXPLORE.EXE Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\DomainSuggestion\NextUpdateDate = "425246019" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$blogger iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Recovery\AdminActive\{8DB4E843-2B50-11EF-B03F-EAEDABA7A252} = "0" iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager IEXPLORE.EXE Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastUpdateHighDateTime = "31113053" IEXPLORE.EXE Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$Telligent iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery\AdminActive = "0" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\LastProcessed = 702bd1625dbfda01 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\HistoryJournalCertificate iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastUpdateLowDateTime = "1651162876" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastUpdateHighDateTime = "31113053" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\LastProcessed = 80e1ce625dbfda01 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main IEXPLORE.EXE Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\Window_Placement = 2c0000000200000003000000ffffffffffffffffffffffffffffffff2400000024000000aa04000089020000 iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery\AdminActive = "1" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastTTLLowDateTime = "1251635200" iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$http://www.typepad.com/ iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch IEXPLORE.EXE Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\HistoryJournalCertificate\NextUpdateDate = "425262613" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastCheckForUpdateLowDateTime = "1651162876" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastUpdateLowDateTime = "1651318938" IEXPLORE.EXE Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage\DecayDateQueue = 01000000d08c9ddf0115d1118c7a00c04fc297eb01000000c517910592b48541be24303fa89e939b0000000002000000000010660000000100002000000005a4c582d56be2af0f93e6525801b8775f203aaa95a455123f3c70f20da31ab9000000000e80000000020000200000002f0b8b6aae223ee38f2454791e6ca87ccd61510064e013bf83cef6e7773caef920000000311029d678b4f83515773c5c6b1a36260cbfa2a43fb7b72c263ad69b1c8c35af40000000beba596b7d705cb00c7d39c5835d8f489cdb216d312ab71f16d6b314e1ef122b4f2161886175d5f8b35cd717a978e50ce2fb3fb37ea184b02c068beaf9dbfa18 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\DomainSuggestion iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead iexplore.exe Set value (data) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\Meta\generator$vBulletin 4 iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Recovery\AdminActive iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\FullScreen = "no" iexplore.exe Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\FlipAhead\FileVersion = "2016061511" iexplore.exe Key created \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\Main\WindowsSearch iexplore.exe Set value (str) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\GPU\AdapterInfo = "vendorId=\"0x10de\",deviceID=\"0x8c\",subSysID=\"0x0\",revision=\"0x0\",version=\"10.0.15063.0\"hypervisor=\"No Hypervisor (No SLAT)\"" IEXPLORE.EXE Set value (int) \REGISTRY\USER\S-1-5-21-3699363923-1875576828-3287151903-1000\Software\Microsoft\Internet Explorer\VersionManager\LastCheckForUpdateLowDateTime = "1651318938" IEXPLORE.EXE -
Suspicious use of FindShellTrayWindow 3 IoCs
Processes:
iexplore.exeIEXPLORE.EXEpid process 4824 iexplore.exe 2060 IEXPLORE.EXE 2060 IEXPLORE.EXE -
Suspicious use of SendNotifyMessage 2 IoCs
Processes:
IEXPLORE.EXEpid process 2060 IEXPLORE.EXE 2060 IEXPLORE.EXE -
Suspicious use of SetWindowsHookEx 6 IoCs
Processes:
iexplore.exeIEXPLORE.EXEpid process 4824 iexplore.exe 4824 iexplore.exe 2060 IEXPLORE.EXE 2060 IEXPLORE.EXE 2060 IEXPLORE.EXE 2060 IEXPLORE.EXE -
Suspicious use of WriteProcessMemory 5 IoCs
Processes:
MSOXMLED.EXEiexplore.exedescription pid process target process PID 204 wrote to memory of 4824 204 MSOXMLED.EXE iexplore.exe PID 204 wrote to memory of 4824 204 MSOXMLED.EXE iexplore.exe PID 4824 wrote to memory of 2060 4824 iexplore.exe IEXPLORE.EXE PID 4824 wrote to memory of 2060 4824 iexplore.exe IEXPLORE.EXE PID 4824 wrote to memory of 2060 4824 iexplore.exe IEXPLORE.EXE
Processes
-
C:\Program Files\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE"C:\Program Files\Microsoft Office\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE" /verb open "C:\Users\Admin\AppData\Local\Temp\Loader\Updater\web.xml"1⤵
- Suspicious use of WriteProcessMemory
-
C:\Program Files\Internet Explorer\iexplore.exe"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\Admin\AppData\Local\Temp\Loader\Updater\web.xml2⤵
- Modifies Internet Explorer settings
- Suspicious use of FindShellTrayWindow
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4824 CREDAT:82945 /prefetch:23⤵
- Modifies Internet Explorer settings
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776Filesize
471B
MD5353d80880163e69df5b6056bd95c4c32
SHA178d105b9d4a87648135886f68ee548b8c3773e7f
SHA256ebf1cf4b34ac839f419ca2cd197cac7935facf09ce3fb9b2ea56473adfa2e1d1
SHA5126854a476e104ce370e7f1fc41ac5cc8415373fd46d1aa170104c303780903e1e24d5352ee91b0a551366bb33304bedcb60ad0e0168cfbc2e8ede5ab4a5915b0d
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776Filesize
404B
MD559841ea352eac4ffa1374ec04a4b7565
SHA18698a341016df29ff0ca680459fd50fbd20d2074
SHA256dd6322a268b9eb3b5a140bc7f3558abd74130c77151666d2319ba9ff32ecddfa
SHA512239cfebade03058d3d22ff65ba3658d76709f9028909af8c56362bc42f146b341797da6f89a5430c71235ac36ddd7ba04fba44aa1bfac8936d849e12a8c51709
-
C:\Users\Admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\verF07A.tmpFilesize
15KB
MD51a545d0052b581fbb2ab4c52133846bc
SHA162f3266a9b9925cd6d98658b92adec673cbe3dd3
SHA256557472aeaebf4c1c800b9df14c190f66d62cbabb011300dbedde2dcddd27a6c1
SHA512bd326d111589d87cd6d019378ec725ac9ac7ad4c36f22453941f7d52f90b747ede4783a83dfff6cae1b3bb46690ad49cffa77f2afda019b22863ac485b406e8d
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\CRDFDX20\suggestions[1].en-USFilesize
17KB
MD55a34cb996293fde2cb7a4ac89587393a
SHA13c96c993500690d1a77873cd62bc639b3a10653f
SHA256c6a5377cbc07eece33790cfc70572e12c7a48ad8296be25c0cc805a1f384dbad
SHA512e1b7d0107733f81937415104e70f68b1be6fd0ca65dccf4ff72637943d44278d3a77f704aedff59d2dbc0d56a609b2590c8ec0dd6bc48ab30f1dad0c07a0a3ee
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCookies\QLMOBKUH.cookieFilesize
541B
MD51d2e86298dc804124266868809c20ba2
SHA17ae55368e7848b69cb93a58c03dfec837bab0c8e
SHA256b3f0adba9698939d6d703ba475f4d41b405c72374020f5311c0f668a555117ab
SHA5128dba795dda09fdc5e9bcda04aeb105899d88ce446f78dd99786645edf500060de0b13b229182036c5a67dd5b5562f299b66a25c30bc7583022911f6c9aec5644
-
memory/204-13-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-19-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-7-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-8-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-10-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-11-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-9-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-0-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-12-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-14-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-18-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-6-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-17-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-16-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-15-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-20-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-5-0x00007FFAACB60000-0x00007FFAACD3B000-memory.dmpFilesize
1.9MB
-
memory/204-4-0x00007FFAACC05000-0x00007FFAACC06000-memory.dmpFilesize
4KB
-
memory/204-3-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-2-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB
-
memory/204-1-0x00007FFA6CBF0000-0x00007FFA6CC00000-memory.dmpFilesize
64KB