Analysis
-
max time kernel
142s -
max time network
154s -
platform
windows10-2004_x64 -
resource
win10v2004-20240226-en -
resource tags
arch:x64arch:x86image:win10v2004-20240226-enlocale:en-usos:windows10-2004-x64system -
submitted
27-06-2024 01:36
Static task
static1
Behavioral task
behavioral1
Sample
c527daf2491bb0c007246173bd7dee7926a01418ae3550f60f6971f2fb8caa94.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
c527daf2491bb0c007246173bd7dee7926a01418ae3550f60f6971f2fb8caa94.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
AdminTools.exe
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
AdminTools.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral5
Sample
Ruchernes.ps1
Resource
win7-20240611-en
Behavioral task
behavioral6
Sample
Ruchernes.ps1
Resource
win10v2004-20240508-en
General
-
Target
AdminTools.exe
-
Size
25KB
-
MD5
24c7684f85c0e61d41c31766197d6061
-
SHA1
2afbed52e13fb8b1f0b3cb786a463400b208049a
-
SHA256
f095c96f8354738f2d272b7837dcde2b6c9e9abdca3efa91c114af87d7590453
-
SHA512
778fd49b8dfd52030c1d0b7e724351ee1d9dcb02017b07af5e8ccfab18bbfcc534ac7fc541c910294b06f0863d3011d19ebc66b947e349e4e02f2884a82f348f
-
SSDEEP
192:hQKgOcvfUkNLH3aXfJ/JcMedTsjEz02It+y5n1gtHYzrqUtEcEjPTx7N6rOE+v13:/7HkdaPPcM+TsJ5Ct4yUtGx0eMDQbz
Malware Config
Signatures
Processes
-
C:\Users\Admin\AppData\Local\Temp\AdminTools.exe"C:\Users\Admin\AppData\Local\Temp\AdminTools.exe"1⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=2232 --field-trial-handle=2284,i,15722001240173834669,15048020084704567542,262144 --variations-seed-version /prefetch:81⤵