Analysis
-
max time kernel
147s -
max time network
151s -
platform
windows11-21h2_x64 -
resource
win11-20240419-en -
resource tags
arch:x64arch:x86image:win11-20240419-enlocale:en-usos:windows11-21h2-x64system -
submitted
26-06-2024 04:22
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe
Resource
win10v2004-20240611-en
3 signatures
150 seconds
General
-
Target
86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe
-
Size
394KB
-
MD5
55f4b847b14147e16ecc74cb592f9fe0
-
SHA1
062735ada0c04c78717dcfeebf692953d3b7ef02
-
SHA256
86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f
-
SHA512
76e10a02bce21be0e4e6d2912480c916f1b8afc4ee91d6b7c53b072649dc0cbbf8482920904402a2ec0d871666ef878d88bb3c562e903fbb426b0247189d8c1d
-
SSDEEP
6144:xLG0ZFpO26y2nkPeiOpW4xa8t9Ohty6MBk:xq0ZPV6y+rjpWmaa9Ohta
Malware Config
Extracted
Family
gcleaner
C2
185.172.128.90
5.42.64.56
185.172.128.69
Signatures
-
Program crash 8 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 3116 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 4484 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 3416 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 2148 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 2328 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 2644 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 2740 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe 1196 4876 WerFault.exe 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exepid process 4876 86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe"C:\Users\Admin\AppData\Local\Temp\86221dac494de8ac19e19fa4f849797f3fc830af3847610a9125b3dd4974a51f.exe"1⤵
- Suspicious behavior: GetForegroundWindowSpam
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 4882⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 7962⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 7962⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 8482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 8882⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 10002⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 10042⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 4876 -s 8002⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 404 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 500 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 520 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 356 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 524 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 516 -p 4876 -ip 48761⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 4876 -ip 48761⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/4876-1-0x00000000024E0000-0x00000000025E0000-memory.dmpFilesize
1024KB
-
memory/4876-3-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB
-
memory/4876-2-0x0000000004090000-0x00000000040CC000-memory.dmpFilesize
240KB
-
memory/4876-4-0x0000000000400000-0x000000000237E000-memory.dmpFilesize
31.5MB
-
memory/4876-6-0x00000000024E0000-0x00000000025E0000-memory.dmpFilesize
1024KB
-
memory/4876-7-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB