Analysis
-
max time kernel
149s -
max time network
151s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
26-06-2024 09:36
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe
Resource
win10v2004-20240508-en
windows10-2004-x64
2 signatures
150 seconds
General
-
Target
2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe
-
Size
246KB
-
MD5
f17cb34bfd02d4a1b5d4f466827e4ae3
-
SHA1
77f70b7f039effe13a78333f0649aad019d5950a
-
SHA256
2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd
-
SHA512
af9e7cfc209352f6021dd6a0f8c9fda7b37ab0af2fbf7fb08ecda1648db9709bcd02c0fbe9d2246d16cb7b432cfc27e6d808f9940ff648f63131532db6d65a9a
-
SSDEEP
3072:1I5tu+QhwdmXIgq9uRNvuQjM+bV+HkcvBOL+sw6mi3K6ATYOCeO5RsNvXQQOUygP:1Iq+Qi6I79+JVM+JXuRi3KXWj5nQO
Malware Config
Extracted
Family
gcleaner
C2
185.172.128.90
5.42.64.56
185.172.128.69
Signatures
-
Program crash 9 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 4164 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 232 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 1984 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 4388 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 4964 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 64 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 832 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 2008 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe 2360 5088 WerFault.exe 2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe"C:\Users\Admin\AppData\Local\Temp\2dc8d72e6eb3d6f198ad5a857c45186e60dc78f73e25676965946635fa3e3ccd.exe"1⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 4522⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 4762⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 7482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 7482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 8002⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 8242⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 9122⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 9162⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5088 -s 7522⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 420 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 184 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 508 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 404 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 504 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 504 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 516 -p 5088 -ip 50881⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 5088 -ip 50881⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/5088-1-0x0000000000740000-0x0000000000840000-memory.dmpFilesize
1024KB
-
memory/5088-3-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB
-
memory/5088-2-0x00000000006B0000-0x00000000006EC000-memory.dmpFilesize
240KB
-
memory/5088-4-0x0000000000400000-0x0000000000447000-memory.dmpFilesize
284KB
-
memory/5088-6-0x0000000000740000-0x0000000000840000-memory.dmpFilesize
1024KB
-
memory/5088-7-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB