Analysis
-
max time kernel
118s -
max time network
118s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
23-06-2024 21:31
Static task
static1
Behavioral task
behavioral1
Sample
Loader/Launcher.dll
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
Loader/Launcher.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
Loader/Loader.exe
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
Loader/Loader.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
Loader/mainf.dll
Resource
win7-20240508-en
Behavioral task
behavioral6
Sample
Loader/mainf.dll
Resource
win10v2004-20240508-en
General
-
Target
Loader/Launcher.dll
-
Size
7.5MB
-
MD5
cbb81f28c5a509e4f7e3e44bc7da74f8
-
SHA1
47145f07bc7d0083d3bd13a9da44bac740952029
-
SHA256
413bf9c2cff6fe7b97eae199683df7f6d648fad4c25cb6d0b7dce335eb69edba
-
SHA512
bc863ebb2f5fd66f342be8befb49889dd275adb15cff95ed378e185190091589c8d1d7a8902ca889a7b2af81588c731bfa0a930f074fecadd9b47a082966079c
-
SSDEEP
98304:koD5geAsEDKN0xOLy2MsmCkQejop7PGXleggxF:kfD/mexOLy0GoNPGXledT
Malware Config
Signatures
-
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
rundll32.exedescription pid process target process PID 2932 wrote to memory of 3024 2932 rundll32.exe WerFault.exe PID 2932 wrote to memory of 3024 2932 rundll32.exe WerFault.exe PID 2932 wrote to memory of 3024 2932 rundll32.exe WerFault.exe