Analysis

  • max time kernel
    140s
  • max time network
    104s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    24-06-2024 22:45

General

  • Target

    Consignment Document PL&BL Draft.exe

  • Size

    330KB

  • MD5

    0b1f9847d93445c91cdfe0c2dd6785c7

  • SHA1

    198b30e2b098300ec51e2e7029ababff142a5e09

  • SHA256

    e92125c96b4bee95fd7b70d867271510071f812699733de75dd5e64636030314

  • SHA512

    1adaa0879bd697ba972fabe8c5407bbf8bf16ea6b55cfbdffd42128174d9f1d8ebe1444a927d0b2ae376563d927467599dfe4e254b096e0f55a5b810ff46fcc1

  • SSDEEP

    3072:NBkfJpRXATwMdFCct+bYGTHbzgxXCXBMz8sfUKVIbzqMmLNer0ABJEREhwBCkXx1:NqjIQYGzghO3Ol68LMJQLHhTbt

Score
7/10

Malware Config

Signatures

  • Loads dropped DLL 2 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Program crash 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 8 IoCs
  • Suspicious use of WriteProcessMemory 3 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\Consignment Document PL&BL Draft.exe
    "C:\Users\Admin\AppData\Local\Temp\Consignment Document PL&BL Draft.exe"
    1⤵
    • Loads dropped DLL
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of WriteProcessMemory
    PID:3184
    • C:\Users\Admin\AppData\Local\Temp\Consignment Document PL&BL Draft.exe
      "C:\Users\Admin\AppData\Local\Temp\Consignment Document PL&BL Draft.exe"
      2⤵
        PID:1476
      • C:\Windows\SysWOW64\WerFault.exe
        C:\Windows\SysWOW64\WerFault.exe -u -p 3184 -s 1000
        2⤵
        • Program crash
        PID:2240
    • C:\Windows\SysWOW64\WerFault.exe
      C:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 3184 -ip 3184
      1⤵
        PID:1636

      Network

      MITRE ATT&CK Matrix ATT&CK v13

      Replay Monitor

      Loading Replay Monitor...

      Downloads

      • C:\Users\Admin\AppData\Local\Temp\nse3895.tmp\System.dll
        Filesize

        11KB

        MD5

        fccff8cb7a1067e23fd2e2b63971a8e1

        SHA1

        30e2a9e137c1223a78a0f7b0bf96a1c361976d91

        SHA256

        6fcea34c8666b06368379c6c402b5321202c11b00889401c743fb96c516c679e

        SHA512

        f4335e84e6f8d70e462a22f1c93d2998673a7616c868177cac3e8784a3be1d7d0bb96f2583fa0ed82f4f2b6b8f5d9b33521c279a42e055d80a94b4f3f1791e0c

      • C:\Users\Admin\AppData\Local\Temp\yrcvb.dll
        Filesize

        11KB

        MD5

        8d80a618809cc8ce5970b0839f0e2b5a

        SHA1

        34af09ca5aa646debe4d2bd06fd5b3c3b7a43b09

        SHA256

        f4163107f632e0b431c38652eb297733f4f01d37576100673a47370da9221159

        SHA512

        21bfab7002044c7b33d99de355b49357ae5c45c8781ae080a906c091621ab55e39444e3ecfe04345022ab214dd50f38df0387a3386e0442312cc614bc8b397bf

      • memory/3184-13-0x0000000010000000-0x0000000010006000-memory.dmp
        Filesize

        24KB

      • memory/3184-14-0x0000000010000000-0x0000000010006000-memory.dmp
        Filesize

        24KB