Overview
overview
10Static
static
100d63eafe7f...99.exe
windows7-x64
80d63eafe7f...99.exe
windows10-2004-x64
8$PLUGINSDI...ge.dll
windows7-x64
1$PLUGINSDI...ge.dll
windows10-2004-x64
1$PLUGINSDI...gs.dll
windows7-x64
3$PLUGINSDI...gs.dll
windows10-2004-x64
31921502319...4.xlam
windows7-x64
101921502319...4.xlam
windows10-2004-x64
127133b9541...e9.vbs
windows7-x64
827133b9541...e9.vbs
windows10-2004-x64
6304278cfa0...1c.xls
windows7-x64
1304278cfa0...1c.xls
windows10-2004-x64
1365771facf...77.exe
windows7-x64
10365771facf...77.exe
windows10-2004-x64
10397900307d...0c.lnk
windows7-x64
3397900307d...0c.lnk
windows10-2004-x64
83d390249d9...ab.lnk
windows7-x64
33d390249d9...ab.lnk
windows10-2004-x64
840e5adc952...73.xls
windows7-x64
140e5adc952...73.xls
windows10-2004-x64
1746afcd799...69.xls
windows7-x64
1746afcd799...69.xls
windows10-2004-x64
185af8304fd...9f.jar
windows7-x64
185af8304fd...9f.jar
windows10-2004-x64
7984646a5a7...41.vbs
windows7-x64
10984646a5a7...41.vbs
windows10-2004-x64
109c33e83331...ce.exe
windows7-x64
109c33e83331...ce.exe
windows10-2004-x64
109f07c02b13...b4.lnk
windows7-x64
39f07c02b13...b4.lnk
windows10-2004-x64
10c0baec4eb2...f.xlam
windows7-x64
10c0baec4eb2...f.xlam
windows10-2004-x64
1Analysis
-
max time kernel
71s -
max time network
54s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
17-06-2024 01:02
Behavioral task
behavioral1
Sample
0d63eafe7f4eebd3b782dd262da6fa3e562c420e0ecfff540ee1a9c5a76b0f99.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
0d63eafe7f4eebd3b782dd262da6fa3e562c420e0ecfff540ee1a9c5a76b0f99.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/BgImage.dll
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/BgImage.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
$PLUGINSDIR/nsDialogs.dll
Resource
win7-20240220-en
Behavioral task
behavioral6
Sample
$PLUGINSDIR/nsDialogs.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
19215023198d9ebe4a626113cc6c001bd4d250ebea69aa25afd483aefd4c0984.xlam
Resource
win7-20240221-en
Behavioral task
behavioral8
Sample
19215023198d9ebe4a626113cc6c001bd4d250ebea69aa25afd483aefd4c0984.xlam
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
27133b9541228c135784f7c6c3bb9425975d7e7880ae278fea040b0ffcb8eee9.vbs
Resource
win7-20240611-en
Behavioral task
behavioral10
Sample
27133b9541228c135784f7c6c3bb9425975d7e7880ae278fea040b0ffcb8eee9.vbs
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
304278cfa0f9f2e81a48c4f23bcb97920b6263c07484b9a0793c2d1b8c65171c.xls
Resource
win7-20231129-en
Behavioral task
behavioral12
Sample
304278cfa0f9f2e81a48c4f23bcb97920b6263c07484b9a0793c2d1b8c65171c.xls
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
365771facf4476f03189fbace015a962f6fd021650f4ebd61acd0c675bc85b77.exe
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
365771facf4476f03189fbace015a962f6fd021650f4ebd61acd0c675bc85b77.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
397900307dd4900066b97d9cdbf0e4cdaf145572b84293e1e08c2a15e7963a0c.lnk
Resource
win7-20240508-en
Behavioral task
behavioral16
Sample
397900307dd4900066b97d9cdbf0e4cdaf145572b84293e1e08c2a15e7963a0c.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
3d390249d9ba45f8e6198dde8319ee8ccd5b9b23921472095ed453544ca537ab.lnk
Resource
win7-20240508-en
Behavioral task
behavioral18
Sample
3d390249d9ba45f8e6198dde8319ee8ccd5b9b23921472095ed453544ca537ab.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls
Resource
win7-20240221-en
Behavioral task
behavioral20
Sample
40e5adc952e8c472e083a539cd67ac339132f2e41a2c99dd3083dd720c041673.xls
Resource
win10v2004-20240611-en
Behavioral task
behavioral21
Sample
746afcd79967881e5a7a21ff847a60c9ef6f1c2dbd796b4ad0c16bc85009d069.xls
Resource
win7-20240508-en
Behavioral task
behavioral22
Sample
746afcd79967881e5a7a21ff847a60c9ef6f1c2dbd796b4ad0c16bc85009d069.xls
Resource
win10v2004-20240508-en
Behavioral task
behavioral23
Sample
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar
Resource
win7-20240220-en
Behavioral task
behavioral24
Sample
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
984646a5a7686265df256e88616dc046b8daa6fbc1807ae67d2933caf0e6af41.vbs
Resource
win7-20240611-en
Behavioral task
behavioral26
Sample
984646a5a7686265df256e88616dc046b8daa6fbc1807ae67d2933caf0e6af41.vbs
Resource
win10v2004-20240226-en
Behavioral task
behavioral27
Sample
9c33e83331c4e2e954f355f453bd32add84016d45e6434d568fb56b690de26ce.exe
Resource
win7-20240611-en
Behavioral task
behavioral28
Sample
9c33e83331c4e2e954f355f453bd32add84016d45e6434d568fb56b690de26ce.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral29
Sample
9f07c02b13a50bb84630841a7a9876c9ced2ab66d406c54f4673c88e7cd70bb4.lnk
Resource
win7-20240508-en
Behavioral task
behavioral30
Sample
9f07c02b13a50bb84630841a7a9876c9ced2ab66d406c54f4673c88e7cd70bb4.lnk
Resource
win10v2004-20240611-en
Behavioral task
behavioral31
Sample
c0baec4eb2deb38c2f86c250a7aae50a417652429439bb5ecce82e8bac6892ef.xlam
Resource
win7-20240221-en
Behavioral task
behavioral32
Sample
c0baec4eb2deb38c2f86c250a7aae50a417652429439bb5ecce82e8bac6892ef.xlam
Resource
win10v2004-20240611-en
General
-
Target
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar
-
Size
448KB
-
MD5
5f44aa92cda88f8b88f783f5ce2df636
-
SHA1
f791bc786571bfb36e94ed6a293fa22304a5df78
-
SHA256
85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f
-
SHA512
446a86271230343e77530136293ff29467d4166f0b812fc6cc99f53a516e492b21f0fe48fdb033f78db8e7a1620c32c00264d995f948f023ea608cdc2ccb5559
-
SSDEEP
12288:c75igiDyZEO28Cabb5Je8wUYFkGnwce4U:8EyWO28CaRJVwdFk2Yh
Malware Config
Signatures
-
Modifies file permissions 1 TTPs 1 IoCs
-
Suspicious use of WriteProcessMemory 2 IoCs
Processes:
java.exedescription pid process target process PID 4888 wrote to memory of 1744 4888 java.exe icacls.exe PID 4888 wrote to memory of 1744 4888 java.exe icacls.exe
Processes
-
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exejava -jar C:\Users\Admin\AppData\Local\Temp\85af8304fde85bfbd5323012e0f79fab0045a85943454c7757dece03686b049f.jar1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\icacls.exeC:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M2⤵
- Modifies file permissions
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestampFilesize
46B
MD56826a1d71b508c5f217b6ea1672d5d5f
SHA13309d7bfc710d9fc68188cff49af75658afaef8b
SHA2564f907d0ec21439c1b062051049a998b3a1c09baab569de78110150e5e78996dd
SHA51298c7cb3c38e46665cdbbd7fd9c7ccb196ba07de6e37acd6cbaeae8fb6dbd75d4c4f58db870d5740008d2d71e2380fd3478fad39c6668c8302ac6daced555855e
-
memory/4888-2-0x000002A6ABBE0000-0x000002A6ABE50000-memory.dmpFilesize
2.4MB
-
memory/4888-12-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-14-0x000002A6ABE50000-0x000002A6ABE60000-memory.dmpFilesize
64KB
-
memory/4888-16-0x000002A6ABE60000-0x000002A6ABE70000-memory.dmpFilesize
64KB
-
memory/4888-21-0x000002A6ABE80000-0x000002A6ABE90000-memory.dmpFilesize
64KB
-
memory/4888-20-0x000002A6ABE70000-0x000002A6ABE80000-memory.dmpFilesize
64KB
-
memory/4888-24-0x000002A6ABEA0000-0x000002A6ABEB0000-memory.dmpFilesize
64KB
-
memory/4888-23-0x000002A6ABE90000-0x000002A6ABEA0000-memory.dmpFilesize
64KB
-
memory/4888-27-0x000002A6ABEB0000-0x000002A6ABEC0000-memory.dmpFilesize
64KB
-
memory/4888-28-0x000002A6ABEC0000-0x000002A6ABED0000-memory.dmpFilesize
64KB
-
memory/4888-30-0x000002A6ABED0000-0x000002A6ABEE0000-memory.dmpFilesize
64KB
-
memory/4888-36-0x000002A6ABF00000-0x000002A6ABF10000-memory.dmpFilesize
64KB
-
memory/4888-35-0x000002A6ABEF0000-0x000002A6ABF00000-memory.dmpFilesize
64KB
-
memory/4888-38-0x000002A6ABF10000-0x000002A6ABF20000-memory.dmpFilesize
64KB
-
memory/4888-34-0x000002A6ABEE0000-0x000002A6ABEF0000-memory.dmpFilesize
64KB
-
memory/4888-45-0x000002A6ABF40000-0x000002A6ABF50000-memory.dmpFilesize
64KB
-
memory/4888-44-0x000002A6ABF30000-0x000002A6ABF40000-memory.dmpFilesize
64KB
-
memory/4888-43-0x000002A6ABF20000-0x000002A6ABF30000-memory.dmpFilesize
64KB
-
memory/4888-56-0x000002A6ABE50000-0x000002A6ABE60000-memory.dmpFilesize
64KB
-
memory/4888-55-0x000002A6ABF70000-0x000002A6ABF80000-memory.dmpFilesize
64KB
-
memory/4888-54-0x000002A6ABF60000-0x000002A6ABF70000-memory.dmpFilesize
64KB
-
memory/4888-53-0x000002A6ABF50000-0x000002A6ABF60000-memory.dmpFilesize
64KB
-
memory/4888-52-0x000002A6ABBE0000-0x000002A6ABE50000-memory.dmpFilesize
2.4MB
-
memory/4888-59-0x000002A6ABF80000-0x000002A6ABF90000-memory.dmpFilesize
64KB
-
memory/4888-58-0x000002A6ABE60000-0x000002A6ABE70000-memory.dmpFilesize
64KB
-
memory/4888-63-0x000002A6ABF90000-0x000002A6ABFA0000-memory.dmpFilesize
64KB
-
memory/4888-62-0x000002A6ABE80000-0x000002A6ABE90000-memory.dmpFilesize
64KB
-
memory/4888-61-0x000002A6ABE70000-0x000002A6ABE80000-memory.dmpFilesize
64KB
-
memory/4888-67-0x000002A6ABEA0000-0x000002A6ABEB0000-memory.dmpFilesize
64KB
-
memory/4888-69-0x000002A6ABFB0000-0x000002A6ABFC0000-memory.dmpFilesize
64KB
-
memory/4888-68-0x000002A6ABFA0000-0x000002A6ABFB0000-memory.dmpFilesize
64KB
-
memory/4888-66-0x000002A6ABE90000-0x000002A6ABEA0000-memory.dmpFilesize
64KB
-
memory/4888-70-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-75-0x000002A6ABFC0000-0x000002A6ABFD0000-memory.dmpFilesize
64KB
-
memory/4888-74-0x000002A6ABEC0000-0x000002A6ABED0000-memory.dmpFilesize
64KB
-
memory/4888-78-0x000002A6ABFD0000-0x000002A6ABFE0000-memory.dmpFilesize
64KB
-
memory/4888-77-0x000002A6ABED0000-0x000002A6ABEE0000-memory.dmpFilesize
64KB
-
memory/4888-73-0x000002A6ABEB0000-0x000002A6ABEC0000-memory.dmpFilesize
64KB
-
memory/4888-82-0x000002A6ABFE0000-0x000002A6ABFF0000-memory.dmpFilesize
64KB
-
memory/4888-81-0x000002A6ABF00000-0x000002A6ABF10000-memory.dmpFilesize
64KB
-
memory/4888-80-0x000002A6ABEF0000-0x000002A6ABF00000-memory.dmpFilesize
64KB
-
memory/4888-79-0x000002A6ABEE0000-0x000002A6ABEF0000-memory.dmpFilesize
64KB
-
memory/4888-87-0x000002A6ABF10000-0x000002A6ABF20000-memory.dmpFilesize
64KB
-
memory/4888-88-0x000002A6ABFF0000-0x000002A6AC000000-memory.dmpFilesize
64KB
-
memory/4888-89-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-90-0x000002A6ABF20000-0x000002A6ABF30000-memory.dmpFilesize
64KB
-
memory/4888-92-0x000002A6ABF40000-0x000002A6ABF50000-memory.dmpFilesize
64KB
-
memory/4888-91-0x000002A6ABF30000-0x000002A6ABF40000-memory.dmpFilesize
64KB
-
memory/4888-94-0x000002A6ABF60000-0x000002A6ABF70000-memory.dmpFilesize
64KB
-
memory/4888-95-0x000002A6ABF70000-0x000002A6ABF80000-memory.dmpFilesize
64KB
-
memory/4888-96-0x000002A6ABF80000-0x000002A6ABF90000-memory.dmpFilesize
64KB
-
memory/4888-97-0x000002A6ABF90000-0x000002A6ABFA0000-memory.dmpFilesize
64KB
-
memory/4888-100-0x000002A6AC000000-0x000002A6AC010000-memory.dmpFilesize
64KB
-
memory/4888-98-0x000002A6ABFA0000-0x000002A6ABFB0000-memory.dmpFilesize
64KB
-
memory/4888-99-0x000002A6ABFB0000-0x000002A6ABFC0000-memory.dmpFilesize
64KB
-
memory/4888-103-0x000002A6AC010000-0x000002A6AC020000-memory.dmpFilesize
64KB
-
memory/4888-102-0x000002A6ABFC0000-0x000002A6ABFD0000-memory.dmpFilesize
64KB
-
memory/4888-106-0x000002A6AC020000-0x000002A6AC030000-memory.dmpFilesize
64KB
-
memory/4888-105-0x000002A6ABFD0000-0x000002A6ABFE0000-memory.dmpFilesize
64KB
-
memory/4888-108-0x000002A6ABFE0000-0x000002A6ABFF0000-memory.dmpFilesize
64KB
-
memory/4888-109-0x000002A6AC030000-0x000002A6AC040000-memory.dmpFilesize
64KB
-
memory/4888-111-0x000002A6ABFF0000-0x000002A6AC000000-memory.dmpFilesize
64KB
-
memory/4888-112-0x000002A6AC040000-0x000002A6AC050000-memory.dmpFilesize
64KB
-
memory/4888-114-0x000002A6AC050000-0x000002A6AC060000-memory.dmpFilesize
64KB
-
memory/4888-116-0x000002A6AC060000-0x000002A6AC070000-memory.dmpFilesize
64KB
-
memory/4888-118-0x000002A6AC070000-0x000002A6AC080000-memory.dmpFilesize
64KB
-
memory/4888-120-0x000002A6AC080000-0x000002A6AC090000-memory.dmpFilesize
64KB
-
memory/4888-124-0x000002A6AC0A0000-0x000002A6AC0B0000-memory.dmpFilesize
64KB
-
memory/4888-123-0x000002A6AC090000-0x000002A6AC0A0000-memory.dmpFilesize
64KB
-
memory/4888-126-0x000002A6AC000000-0x000002A6AC010000-memory.dmpFilesize
64KB
-
memory/4888-127-0x000002A6AC0B0000-0x000002A6AC0C0000-memory.dmpFilesize
64KB
-
memory/4888-147-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-146-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-150-0x000002A6AC010000-0x000002A6AC020000-memory.dmpFilesize
64KB
-
memory/4888-151-0x000002A6AC0C0000-0x000002A6AC0D0000-memory.dmpFilesize
64KB
-
memory/4888-153-0x000002A6AC020000-0x000002A6AC030000-memory.dmpFilesize
64KB
-
memory/4888-154-0x000002A6AC0D0000-0x000002A6AC0E0000-memory.dmpFilesize
64KB
-
memory/4888-156-0x000002A6AC030000-0x000002A6AC040000-memory.dmpFilesize
64KB
-
memory/4888-157-0x000002A6AC0E0000-0x000002A6AC0F0000-memory.dmpFilesize
64KB
-
memory/4888-160-0x000002A6AC0F0000-0x000002A6AC100000-memory.dmpFilesize
64KB
-
memory/4888-159-0x000002A6AC040000-0x000002A6AC050000-memory.dmpFilesize
64KB
-
memory/4888-164-0x000002A6AC100000-0x000002A6AC110000-memory.dmpFilesize
64KB
-
memory/4888-165-0x000002A6AC110000-0x000002A6AC120000-memory.dmpFilesize
64KB
-
memory/4888-163-0x000002A6AC050000-0x000002A6AC060000-memory.dmpFilesize
64KB
-
memory/4888-170-0x000002A6AC130000-0x000002A6AC140000-memory.dmpFilesize
64KB
-
memory/4888-169-0x000002A6AC120000-0x000002A6AC130000-memory.dmpFilesize
64KB
-
memory/4888-168-0x000002A6AC060000-0x000002A6AC070000-memory.dmpFilesize
64KB
-
memory/4888-172-0x000002A6AC070000-0x000002A6AC080000-memory.dmpFilesize
64KB
-
memory/4888-173-0x000002A6AC140000-0x000002A6AC150000-memory.dmpFilesize
64KB
-
memory/4888-178-0x000002A6AC160000-0x000002A6AC170000-memory.dmpFilesize
64KB
-
memory/4888-177-0x000002A6AC150000-0x000002A6AC160000-memory.dmpFilesize
64KB
-
memory/4888-176-0x000002A6AC080000-0x000002A6AC090000-memory.dmpFilesize
64KB
-
memory/4888-185-0x000002A6AC180000-0x000002A6AC190000-memory.dmpFilesize
64KB
-
memory/4888-184-0x000002A6AC170000-0x000002A6AC180000-memory.dmpFilesize
64KB
-
memory/4888-183-0x000002A6AC0A0000-0x000002A6AC0B0000-memory.dmpFilesize
64KB
-
memory/4888-182-0x000002A6AC090000-0x000002A6AC0A0000-memory.dmpFilesize
64KB
-
memory/4888-188-0x000002A6AC190000-0x000002A6AC1A0000-memory.dmpFilesize
64KB
-
memory/4888-187-0x000002A6AC0B0000-0x000002A6AC0C0000-memory.dmpFilesize
64KB
-
memory/4888-190-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB
-
memory/4888-213-0x000002A6AC1A0000-0x000002A6AC1B0000-memory.dmpFilesize
64KB
-
memory/4888-212-0x000002A6AC0C0000-0x000002A6AC0D0000-memory.dmpFilesize
64KB
-
memory/4888-216-0x000002A6AC0D0000-0x000002A6AC0E0000-memory.dmpFilesize
64KB
-
memory/4888-272-0x000002A6ABBC0000-0x000002A6ABBC1000-memory.dmpFilesize
4KB