Analysis
-
max time kernel
149s -
max time network
151s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
26-06-2024 12:59
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe
Resource
win10v2004-20240508-en
windows10-2004-x64
2 signatures
150 seconds
General
-
Target
5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe
-
Size
246KB
-
MD5
d9af65970b779b1ab9438022a342927b
-
SHA1
8e6c3f94b58c12f9360be85252e69ec1cc1fb358
-
SHA256
5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69
-
SHA512
1f4dbc10320bfe916b326442998b8ce39bee054b4f5b49c2e03b9d5e7a51be4a524f2af8ea1588591bebbab0314963c41a755a91066c08ca7a458ba2965d547a
-
SSDEEP
3072:gdrSjQ5c5vkC5aZ+zuvNKsaU6AQJuDX6V3M9tz2YjQBSb8zu0XgTfM1x:gcjQ8b5QlKswdUX19tzXGSb8v
Malware Config
Extracted
Family
gcleaner
C2
185.172.128.90
5.42.64.56
185.172.128.69
Signatures
-
Program crash 10 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 388 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 696 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 1028 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 2408 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 1136 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 4196 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 3692 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 3804 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 1796 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe 2864 2768 WerFault.exe 5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe"C:\Users\Admin\AppData\Local\Temp\5907c40a71c4ea5fc3d40e70015850fdd36ca7cb869c22d23467636b9a5b2b69.exe"1⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 4522⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 4522⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 7482⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 7882⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 8082⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 7762⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 9122⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 9442⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 10122⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 2768 -s 7522⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 436 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 412 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 460 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 436 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 436 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 456 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 460 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 452 -p 2768 -ip 27681⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 2768 -ip 27681⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2768-1-0x00000000006B0000-0x00000000007B0000-memory.dmpFilesize
1024KB
-
memory/2768-3-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB
-
memory/2768-2-0x0000000000610000-0x000000000064C000-memory.dmpFilesize
240KB
-
memory/2768-4-0x0000000000400000-0x0000000000447000-memory.dmpFilesize
284KB
-
memory/2768-6-0x00000000006B0000-0x00000000007B0000-memory.dmpFilesize
1024KB
-
memory/2768-7-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB