Analysis
-
max time kernel
148s -
max time network
158s -
platform
windows11-21h2_x64 -
resource
win11-20240508-en -
resource tags
arch:x64arch:x86image:win11-20240508-enlocale:en-usos:windows11-21h2-x64system -
submitted
25-06-2024 19:46
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe
Resource
win10v2004-20240611-en
8 signatures
150 seconds
General
-
Target
5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe
-
Size
393KB
-
MD5
24da98fdaea0c10333d7e76961364b8b
-
SHA1
51b07f1d4f0bc033f01a080bf8a223e25ab01096
-
SHA256
5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7
-
SHA512
ef7ea515cfb1c694a26e557adf2dff8f27c88eafef7d145f6b377419e62591a0b962feda5cb72db48384260dd03dc4d3f430d1f0e9bd6096a5b004bf55f71463
-
SSDEEP
6144:SLoMkVriKlRdB9TImCYNPKrhOJxKK9I35coVK84Nz:ScMUrz1B924PK1OJxKKuGoEbN
Malware Config
Extracted
Family
gcleaner
C2
185.172.128.90
5.42.64.56
185.172.128.69
Signatures
-
Program crash 8 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 1912 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 4804 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 2036 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 1420 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 1168 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 4392 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 2256 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe 1020 3076 WerFault.exe 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exepid process 3076 5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe"C:\Users\Admin\AppData\Local\Temp\5f9fca740396ba14711a1b715aa611ed17fc2f833ae15c2ac582fbda3b2246d7.exe"1⤵
- Suspicious behavior: GetForegroundWindowSpam
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 4042⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 7962⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 8162⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 8562⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 9082⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 9962⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 10482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3076 -s 8002⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 492 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 496 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 512 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 416 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 3076 -ip 30761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 3076 -ip 30761⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/3076-1-0x0000000002660000-0x0000000002760000-memory.dmpFilesize
1024KB
-
memory/3076-3-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB
-
memory/3076-2-0x00000000025E0000-0x000000000261C000-memory.dmpFilesize
240KB
-
memory/3076-4-0x0000000000400000-0x000000000237E000-memory.dmpFilesize
31.5MB
-
memory/3076-5-0x0000000002660000-0x0000000002760000-memory.dmpFilesize
1024KB
-
memory/3076-7-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB