Analysis
-
max time kernel
145s -
max time network
147s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
25-06-2024 11:54
Static task
static1
URLScan task
urlscan1
Behavioral task
behavioral1
Sample
https://u.to/mcy-IA
Resource
win10v2004-20240508-en
General
-
Target
https://u.to/mcy-IA
Malware Config
Signatures
-
Enumerates system info in registry 2 TTPs 3 IoCs
Processes:
msedge.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS msedge.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemManufacturer msedge.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemProductName msedge.exe -
Suspicious behavior: EnumeratesProcesses 10 IoCs
Processes:
msedge.exemsedge.exeidentity_helper.exemsedge.exepid process 1308 msedge.exe 1308 msedge.exe 4584 msedge.exe 4584 msedge.exe 3344 identity_helper.exe 3344 identity_helper.exe 1280 msedge.exe 1280 msedge.exe 1280 msedge.exe 1280 msedge.exe -
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary 7 IoCs
Processes:
msedge.exepid process 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe -
Suspicious use of FindShellTrayWindow 25 IoCs
Processes:
msedge.exepid process 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe -
Suspicious use of SendNotifyMessage 24 IoCs
Processes:
msedge.exepid process 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe 4584 msedge.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
msedge.exedescription pid process target process PID 4584 wrote to memory of 368 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 368 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 3188 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 1308 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 1308 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe PID 4584 wrote to memory of 4204 4584 msedge.exe msedge.exe
Processes
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://u.to/mcy-IA1⤵
- Enumerates system info in registry
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=92.0.4515.131 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=92.0.902.67 --initial-client-data=0xfc,0x100,0x104,0xd8,0x108,0x7ff8c04046f8,0x7ff8c0404708,0x7ff8c04047182⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --gpu-preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHAAAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=2088 /prefetch:22⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 /prefetch:32⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2832 /prefetch:82⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3340 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3348 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5060 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\identity_helper.exe"C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5248 /prefetch:82⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\identity_helper.exe"C:\Program Files (x86)\Microsoft\Edge\Application\92.0.902.67\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5248 /prefetch:82⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4144 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --instant-process --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5392 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5012 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --lang=en-US --disable-client-side-phishing-detection --instant-process --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5168 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=2064,11791602350486390193,12170246237976290664,131072 --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=4318 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.546 --gpu-preferences=UAAAAAAAAADoAAAQAAAAAAAAAAAAAAAAAABgAAAEAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHAAAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=3124 /prefetch:22⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Windows\System32\CompPkgSrv.exeC:\Windows\System32\CompPkgSrv.exe -Embedding1⤵
-
C:\Windows\System32\CompPkgSrv.exeC:\Windows\System32\CompPkgSrv.exe -Embedding1⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datFilesize
152B
MD5a8e767fd33edd97d306efb6905f93252
SHA1a6f80ace2b57599f64b0ae3c7381f34e9456f9d3
SHA256c8077a9fc79e2691ef321d556c4ce9933ca0570f2bbaa32fa32999dfd5f908bb
SHA51207b748582fe222795bce74919aa06e9a09025c14493edb6f3b1f112d9a97ac2225fe0904cac9adf2a62c98c42f7877076e409803014f0afd395f4cc8be207241
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datFilesize
152B
MD5439b5e04ca18c7fb02cf406e6eb24167
SHA1e0c5bb6216903934726e3570b7d63295b9d28987
SHA256247d0658695a1eb44924a32363906e37e9864ba742fe35362a71f3a520ad2654
SHA512d0241e397060eebd4535197de4f1ae925aa88ae413a3a9ded6e856b356c4324dfd45dddfef9a536f04e4a258e8fe5dc1586d92d1d56b649f75ded8eddeb1f3e2
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\the-real-indexFilesize
384B
MD5c1b9418e271e79173e426801be0c1c00
SHA1d8bf7af559bdf2b4b0e1aed1160990562c54ed44
SHA2567a89f4f4d00de43bd4ae0e99dfaa81298c61771f9dee554d10c890476eac031e
SHA512db32ad367dfff1fa5cb81c0782d86b39cf625148f5be86a2baf0d97ba4fc1ff0257f5b2a5004c7bb0800844dfb3b129aca53b9dfe4533599e24e696d64dcff31
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Network Persistent StateFilesize
428B
MD5d5c0d69b7320b64ec550d8a8fe3f653e
SHA103d594a223da35961dfd85cb3897a5a87d38874e
SHA256510e7efb65680395c614eba93bed8ee006fd1375c8ba8b1062a49f5a71d35f2e
SHA5126f2610e2f12d80190210123758e9d246046738e785ec0d8dd369fc67562b36cba34cf3fdd62829b7036d5c1d2849e1816422b382107b14d8f1ff12587375d81e
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\PreferencesFilesize
5KB
MD5594adc39470e73a082bd65517f22beb0
SHA1ad2d412189671f5e72a65fd5bba0c2ad41120b95
SHA2560212ff45aa7e2911f39f77c0328b5e7d4614ef893c7885ede915a6543d146c80
SHA512995dd00c8c9c43aa8cd8ed33a5ff24483d90d2c1a701f1013127f0ddb05834f48e16bbb9fa34f0b68ec090c9bfb52f91a10619ee58b69a5a72607ac3c339fafc
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\PreferencesFilesize
6KB
MD519a73eb18707fa63b3c952efdf15d91a
SHA130e7be94b021c795da2e2c4fb363595f225346d8
SHA25690e8719ff875be66b0e384303ad2fab32bddf61adfc2c0de07f3e424e541406e
SHA51277a5a8701d07cd719e824468b9a681d9d44da689617de4ce084005626c467cf7c749e5bfffd2e7ba9ed9287bd9eb0691212c823b3d2695b83c9359dc449b9792
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\CURRENTFilesize
16B
MD56752a1d65b201c13b62ea44016eb221f
SHA158ecf154d01a62233ed7fb494ace3c3d4ffce08b
SHA2560861415cada612ea5834d56e2cf1055d3e63979b69eb71d32ae9ae394d8306cd
SHA5129cfd838d3fb570b44fc3461623ab2296123404c6c8f576b0de0aabd9a6020840d4c9125eb679ed384170dbcaac2fa30dc7fa9ee5b77d6df7c344a0aa030e0389
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Local StateFilesize
10KB
MD517f0b3c61f181360132a6fc1c47a453f
SHA15c336422315c424e7d63ffa4b8d101810e234dbb
SHA256ffd38845ed2a31ffe9bc223ca5690a1744240fca43f2c1edea3b8d6adc27b0e5
SHA512c9d544fd770c5f53bbcdbe9c2e2d6917ae9ba8133216c71f396405bd76237b22234e74366563ba44271465097cf1e2b92db7b3738cf481faa8300c6eb4d65211
-
\??\pipe\LOCAL\crashpad_4584_DOJMYFCPYLNPVDZCMD5
d41d8cd98f00b204e9800998ecf8427e
SHA1da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA512cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e