Analysis
-
max time kernel
142s -
max time network
144s -
platform
windows11-21h2_x64 -
resource
win11-20240611-en -
resource tags
arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system -
submitted
26-06-2024 19:11
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe
Resource
win10v2004-20240508-en
2 signatures
150 seconds
General
-
Target
58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe
-
Size
246KB
-
MD5
06da4f2ff17d452e476c792e51ce750b
-
SHA1
99fc4fa3196a07965823739ca70c5430a7270873
-
SHA256
58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d
-
SHA512
f14ee079f165cec97bc7a93807040aceeafc6ecd16016a38c8aa73097bbf1d9cc2c78b8f80c707c8a3ad2ad67f2169858587100d83e02749b97b7332281cce0a
-
SSDEEP
6144:KV2WyQlHXz2IYDyKsIdQu6go2Kt2vGJvMD:KV2WyQl3mxslu69l2+ZMD
Malware Config
Extracted
Family
gcleaner
C2
185.172.128.90
5.42.64.56
185.172.128.69
Signatures
-
Program crash 9 IoCs
Processes:
WerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exeWerFault.exepid pid_target process target process 1000 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 420 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 3480 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 3140 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 3568 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 1208 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 5116 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 3744 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe 2264 5036 WerFault.exe 58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe"C:\Users\Admin\AppData\Local\Temp\58d0026410046114d7f239f2e82bb26251a6bed96ac98a3d89d3b88e0d67f48d.exe"1⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 4802⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 4842⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 7802⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 8202⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 8202⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 8562⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 9842⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 9882⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 5036 -s 7842⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 480 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 512 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 432 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 504 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 472 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 356 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 504 -p 5036 -ip 50361⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 5036 -ip 50361⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/5036-1-0x00000000005A0000-0x00000000006A0000-memory.dmpFilesize
1024KB
-
memory/5036-3-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB
-
memory/5036-2-0x0000000002150000-0x000000000218C000-memory.dmpFilesize
240KB
-
memory/5036-4-0x0000000000400000-0x0000000000447000-memory.dmpFilesize
284KB
-
memory/5036-6-0x00000000005A0000-0x00000000006A0000-memory.dmpFilesize
1024KB
-
memory/5036-7-0x0000000000400000-0x0000000000440000-memory.dmpFilesize
256KB