Overview
overview
10Static
static
3__x64___se...ip.dll
windows10-2004-x64
8__x64___se...tl.dll
windows10-2004-x64
1__x64___se...ps.dll
windows10-2004-x64
5__x64___se...um.dll
windows10-2004-x64
7__x64___se...el.dll
windows10-2004-x64
1__x64___se...nd.dll
windows10-2004-x64
1__x64___se...eg.dll
windows10-2004-x64
1__x64___se...vc.dll
windows10-2004-x64
1__x64___se...ep.dll
windows10-2004-x64
1__x64___se...fm.dll
windows10-2004-x64
1__x64___se...sh.dll
windows10-2004-x64
1__x64___se...is.dll
windows10-2004-x64
1__x64___se...ip.dll
windows10-2004-x64
8__x64___se...or.dll
windows10-2004-x64
1__x64___se...um.dll
windows10-2004-x64
1__x64___se...ui.dll
windows10-2004-x64
1__x64___se...up.msi
windows7-x64
6__x64___se...up.msi
windows10-2004-x64
10__x64___se...PS.dll
windows10-2004-x64
1__x64___se...pi.dll
windows10-2004-x64
1__x64___se...vc.dll
windows10-2004-x64
1__x64___se...ge.dll
windows10-2004-x64
1Analysis
-
max time kernel
139s -
max time network
126s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
23-06-2024 14:14
Static task
static1
Behavioral task
behavioral1
Sample
__x64___setup___x32__/AppxSip/AppxSip.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral2
Sample
__x64___setup___x32__/AppxSip/MSVidCtl.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
__x64___setup___x32__/AppxSip/deploymentcsps.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral4
Sample
__x64___setup___x32__/AppxSip/devenum.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
__x64___setup___x32__/dsreg/dcntel.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral6
Sample
__x64___setup___x32__/dsreg/dsound.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
__x64___setup___x32__/dsreg/dsreg.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral8
Sample
__x64___setup___x32__/dsreg/sensrsvc.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
__x64___setup___x32__/netprofm/TapiSysprep.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral10
Sample
__x64___setup___x32__/netprofm/netprofm.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
__x64___setup___x32__/netprofm/rpcnsh.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral12
Sample
__x64___setup___x32__/netprofm/socialapis.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
__x64___setup___x32__/pcwum/AppxSip.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral14
Sample
__x64___setup___x32__/pcwum/asferror.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
__x64___setup___x32__/pcwum/pcwum.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral16
Sample
__x64___setup___x32__/pcwum/pdhui.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
__x64___setup___x32__/setup.msi
Resource
win7-20240221-en
Behavioral task
behavioral18
Sample
__x64___setup___x32__/setup.msi
Resource
win10v2004-20240226-en
Behavioral task
behavioral19
Sample
__x64___setup___x32__/wcimage/SEMgrPS.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral20
Sample
__x64___setup___x32__/wcimage/SensorsApi.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral21
Sample
__x64___setup___x32__/wcimage/netprofmsvc.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral22
Sample
__x64___setup___x32__/wcimage/wcimage.dll
Resource
win10v2004-20240611-en
General
-
Target
__x64___setup___x32__/AppxSip/deploymentcsps.dll
-
Size
76KB
-
MD5
1d6dffb182135656f682353bf01d3bf1
-
SHA1
e6a1c4915364e4ce5bb90b51b38dbb45007dbd2b
-
SHA256
d3ecce1709057d83119d2fc9295848dc096ebf682aea0e9bda49e31bd5397fda
-
SHA512
754a746b08074db21cf72d1b3b9574ba75b7c893ea4cdbf8cddfbd7ffe206005172e5acc4bcfd125e88226bab5a60334572a0722167eb93b7f4d73e7b7b364b8
-
SSDEEP
1536:ecB5LC+IF7VPfLhS4eq/PblCVouzRh/DWb+7xAib8CCRhl5glvNtr:ecBEpPg6zkVouz7Da+2ib8CCRP56L
Malware Config
Signatures
-
Drops file in System32 directory 4 IoCs
Processes:
rundll32.exedescription ioc process File opened for modification C:\Windows\system32\LogFiles\deploymentcsps\setuperr.log rundll32.exe File opened for modification C:\Windows\system32\LogFiles\deploymentcsps\diagerr.xml rundll32.exe File opened for modification C:\Windows\system32\LogFiles\deploymentcsps\diagwrn.xml rundll32.exe File opened for modification C:\Windows\system32\LogFiles\deploymentcsps\setupact.log rundll32.exe