Resubmissions
19-06-2024 21:00
240619-ztfnva1fkd 1019-06-2024 20:53
240619-zpdnpawalj 1019-06-2024 20:28
240619-y876zazfpd 10Analysis
-
max time kernel
359s -
max time network
333s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
19-06-2024 20:53
Behavioral task
behavioral1
Sample
hijackloader_stealc_new_hash.exe
Resource
win10v2004-20240508-en
General
-
Target
hijackloader_stealc_new_hash.exe
-
Size
922KB
-
MD5
4081d00fabf6ba8e9eb58202ea053735
-
SHA1
22afaf01961b36e741d104bd3b96ce8df4fbf519
-
SHA256
ef62979af506ec3ac2c176bc667465940ca4a1e4f8229e0bc992fec715d43ae8
-
SHA512
1434efa23afd3cb95d0a55a17b246cbee0179072660ce0458701cf9b3b8075217b0864be09a2bbc428c2b9f2253cace6361f874ad8f1d2f472f9f34bd0bc4eda
-
SSDEEP
24576:e8inyEBCZN5hoVlnJXzJ/SEVSoMAALia4:DgABuxF/SRF4
Malware Config
Extracted
stealc
cozy15
http://193.163.7.88
-
url_path
/a69d09b357e06b52.php
Signatures
-
Detects HijackLoader (aka IDAT Loader) 1 IoCs
Processes:
resource yara_rule behavioral1/memory/2272-0-0x00000000007C0000-0x00000000008A8000-memory.dmp family_hijackloader -
HijackLoader
HijackLoader is a multistage loader first seen in 2023.
-
Deletes itself 1 IoCs
Processes:
cmd.exepid process 960 cmd.exe -
Suspicious use of SetThreadContext 1 IoCs
Processes:
hijackloader_stealc_new_hash.exedescription pid process target process PID 2272 set thread context of 960 2272 hijackloader_stealc_new_hash.exe cmd.exe -
Checks SCSI registry key(s) 3 TTPs 3 IoCs
SCSI information is often read in order to detect sandboxing environments.
Processes:
taskmgr.exedescription ioc process Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000 taskmgr.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\Properties\{b725f130-47ef-101a-a5f1-02608c9eebac}\000A taskmgr.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\FriendlyName taskmgr.exe -
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
hijackloader_stealc_new_hash.exepowershell.execmd.exetaskmgr.exepid process 2272 hijackloader_stealc_new_hash.exe 2272 hijackloader_stealc_new_hash.exe 4464 powershell.exe 4464 powershell.exe 960 cmd.exe 960 cmd.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
taskmgr.exepid process 2164 taskmgr.exe -
Suspicious behavior: MapViewOfSection 2 IoCs
Processes:
hijackloader_stealc_new_hash.execmd.exepid process 2272 hijackloader_stealc_new_hash.exe 960 cmd.exe -
Suspicious use of AdjustPrivilegeToken 4 IoCs
Processes:
powershell.exetaskmgr.exedescription pid process Token: SeDebugPrivilege 4464 powershell.exe Token: SeDebugPrivilege 2164 taskmgr.exe Token: SeSystemProfilePrivilege 2164 taskmgr.exe Token: SeCreateGlobalPrivilege 2164 taskmgr.exe -
Suspicious use of FindShellTrayWindow 64 IoCs
Processes:
taskmgr.exepid process 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe -
Suspicious use of SendNotifyMessage 64 IoCs
Processes:
taskmgr.exepid process 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe 2164 taskmgr.exe -
Suspicious use of WriteProcessMemory 8 IoCs
Processes:
hijackloader_stealc_new_hash.execmd.exedescription pid process target process PID 2272 wrote to memory of 960 2272 hijackloader_stealc_new_hash.exe cmd.exe PID 2272 wrote to memory of 960 2272 hijackloader_stealc_new_hash.exe cmd.exe PID 2272 wrote to memory of 960 2272 hijackloader_stealc_new_hash.exe cmd.exe PID 2272 wrote to memory of 960 2272 hijackloader_stealc_new_hash.exe cmd.exe PID 960 wrote to memory of 4012 960 cmd.exe explorer.exe PID 960 wrote to memory of 4012 960 cmd.exe explorer.exe PID 960 wrote to memory of 4012 960 cmd.exe explorer.exe PID 960 wrote to memory of 4012 960 cmd.exe explorer.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\hijackloader_stealc_new_hash.exe"C:\Users\Admin\AppData\Local\Temp\hijackloader_stealc_new_hash.exe"1⤵
- Suspicious use of SetThreadContext
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe2⤵
- Deletes itself
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\explorer.exeC:\Windows\SysWOW64\explorer.exe3⤵
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"1⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\system32\taskmgr.exe"C:\Windows\system32\taskmgr.exe" /41⤵
- Checks SCSI registry key(s)
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_ibyitawl.2up.ps1Filesize
60B
MD5d17fe0a3f47be24a6453e9ef58c94641
SHA16ab83620379fc69f80c0242105ddffd7d98d5d9d
SHA25696ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
SHA5125b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82
-
C:\Users\Admin\AppData\Local\Temp\a34d791aFilesize
861KB
MD54ebe8fc86c2e9fe9a1a54b8873d1e61a
SHA100801897c657083cef0b54d661013bf491bdc497
SHA2566776548198efb97abbfdfc0627d00b555fab07b3d79fe0bbe97f0a5bd7fe9bdd
SHA5125bb3fee714a80fc9f3d5d9e23436f16f08a5cb8dd2aa00a765bfe8fdd4642b30de9196ff11668b390c345dde47ee19de4a58b1d62032cef0deec23de772ad01e
-
memory/960-24-0x0000000074C71000-0x0000000074C7F000-memory.dmpFilesize
56KB
-
memory/960-35-0x0000000074C71000-0x0000000074C7F000-memory.dmpFilesize
56KB
-
memory/960-33-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/960-29-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/960-28-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/960-26-0x00007FFAFF090000-0x00007FFAFF285000-memory.dmpFilesize
2.0MB
-
memory/2164-51-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-55-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-53-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-54-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-45-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-52-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-44-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-50-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-46-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2164-56-0x00000209D5450000-0x00000209D5451000-memory.dmpFilesize
4KB
-
memory/2272-3-0x0000000074C82000-0x0000000074C84000-memory.dmpFilesize
8KB
-
memory/2272-0-0x00000000007C0000-0x00000000008A8000-memory.dmpFilesize
928KB
-
memory/2272-2-0x00007FFAFF090000-0x00007FFAFF285000-memory.dmpFilesize
2.0MB
-
memory/2272-1-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/2272-4-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/2272-22-0x0000000074C70000-0x0000000074DEB000-memory.dmpFilesize
1.5MB
-
memory/4012-34-0x0000000000230000-0x000000000046C000-memory.dmpFilesize
2.2MB
-
memory/4012-36-0x00007FFAFF090000-0x00007FFAFF285000-memory.dmpFilesize
2.0MB
-
memory/4012-37-0x0000000000230000-0x000000000046C000-memory.dmpFilesize
2.2MB
-
memory/4012-40-0x0000000000230000-0x000000000046C000-memory.dmpFilesize
2.2MB
-
memory/4464-19-0x00007FFADFD30000-0x00007FFAE07F1000-memory.dmpFilesize
10.8MB
-
memory/4464-32-0x00007FFADFD30000-0x00007FFAE07F1000-memory.dmpFilesize
10.8MB
-
memory/4464-31-0x00007FFADFD33000-0x00007FFADFD35000-memory.dmpFilesize
8KB
-
memory/4464-21-0x000001CC4CA70000-0x000001CC4CAE6000-memory.dmpFilesize
472KB
-
memory/4464-20-0x000001CC4C9A0000-0x000001CC4C9E4000-memory.dmpFilesize
272KB
-
memory/4464-18-0x00007FFADFD30000-0x00007FFAE07F1000-memory.dmpFilesize
10.8MB
-
memory/4464-17-0x000001CC4BC70000-0x000001CC4BC92000-memory.dmpFilesize
136KB
-
memory/4464-7-0x00007FFADFD33000-0x00007FFADFD35000-memory.dmpFilesize
8KB