Analysis
-
max time kernel
119s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
24-06-2024 22:43
Static task
static1
Behavioral task
behavioral1
Sample
main.py
Resource
win7-20240508-en
4 signatures
150 seconds
Behavioral task
behavioral2
Sample
main.py
Resource
win10v2004-20240611-en
lummarhadamanthysdiscoveryevasionexecutionmotwpersistencephishingprivilege_escalationpyinstallerstealer
42 signatures
150 seconds
General
-
Target
main.py
-
Size
111KB
-
MD5
74e88b3a5e1a99f8da4bb70196118a2a
-
SHA1
6fe34053ff448ffb53c9b09d5ba62c6561dc8b25
-
SHA256
6ed72b789e722b398defd07bd4bd88b390f788128c20938bb72c8ddb93efee55
-
SHA512
d06927ee30219346bc9557d6b5e5c56329e4d293b150361103df679763d70857284f51398d33fec9e2c2a4ed901896bb2d01b38d237aa568bd2bd988b51ecff8
-
SSDEEP
3072:p6ZDuGpHazDq5SRsKj1HcXoNFi66sCowjrMrhps7xw:p6ZDuGpHazD5sKFcXofV6sCoErMrhpsS
Score
3/10
Malware Config
Signatures
-
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies registry class 1 IoCs
Processes:
rundll32.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-3691908287-3775019229-3534252667-1000_Classes\Local Settings rundll32.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
rundll32.exepid process 1832 rundll32.exe -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
cmd.exedescription pid process target process PID 1896 wrote to memory of 1832 1896 cmd.exe rundll32.exe PID 1896 wrote to memory of 1832 1896 cmd.exe rundll32.exe PID 1896 wrote to memory of 1832 1896 cmd.exe rundll32.exe
Processes
-
C:\Windows\system32\cmd.execmd /c C:\Users\Admin\AppData\Local\Temp\main.py1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\rundll32.exe"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\Admin\AppData\Local\Temp\main.py2⤵
- Modifies registry class
- Suspicious behavior: GetForegroundWindowSpam