Analysis
-
max time kernel
51s -
max time network
52s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
27-06-2024 13:39
Static task
static1
Behavioral task
behavioral1
Sample
Medisave Order 180827.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
Medisave Order 180827.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/System.dll
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/System.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
8d144.dll
Resource
win7-20240508-en
Behavioral task
behavioral6
Sample
8d144.dll
Resource
win10v2004-20240508-en
General
-
Target
Medisave Order 180827.exe
-
Size
684KB
-
MD5
33a761dbe5930c762f7f88f7d733a7fe
-
SHA1
886c6d95005d2d5e9b2b9cb3f994826e49ba512e
-
SHA256
9fb198089a3815b1b5ead8e5c11c087a92aa37769e3ab9fc3d09646557743d14
-
SHA512
1f2488e3350451b77fe8abbeca5589d2ac4558b582dbaaddac16f2dc89cda6a4d00fcb2d4b287ab13cd0dbcab11fdb598a21aec1c524cc65ea56f6bc1596e67f
-
SSDEEP
12288:NiDH1gDKcFRdrZjtE4rByjrhw6ct8NCmdyfwasqipKO29cX:QgDKcFRdrF240jW3tsdyRipKO29cX
Malware Config
Signatures
-
Loads dropped DLL 2 IoCs
Processes:
Medisave Order 180827.exepid process 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Program crash 1 IoCs
Processes:
WerFault.exepid pid_target process target process 3784 1828 WerFault.exe Medisave Order 180827.exe -
Suspicious behavior: EnumeratesProcesses 8 IoCs
Processes:
Medisave Order 180827.exepid process 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe 1828 Medisave Order 180827.exe -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
Medisave Order 180827.exedescription pid process target process PID 1828 wrote to memory of 560 1828 Medisave Order 180827.exe Medisave Order 180827.exe PID 1828 wrote to memory of 560 1828 Medisave Order 180827.exe Medisave Order 180827.exe PID 1828 wrote to memory of 560 1828 Medisave Order 180827.exe Medisave Order 180827.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\Medisave Order 180827.exe"C:\Users\Admin\AppData\Local\Temp\Medisave Order 180827.exe"1⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\Medisave Order 180827.exe"C:\Users\Admin\AppData\Local\Temp\Medisave Order 180827.exe"2⤵
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 1828 -s 10002⤵
- Program crash
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 1828 -ip 18281⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\8d144.dllFilesize
10KB
MD5fcaca1b9ad5fe0bfed523839d37ecf27
SHA166fdce05606bc861b42fec41b0505668ac21defe
SHA2563f36bb6084f358696601a687bee93c006bdbb4155a16603ad350d83093a94417
SHA51241b2144eef175e61a9dc417dd8556f653268584ef82c44132b2d505f00dad488dffce370beffeabf322ecf8cfa3cdad6f80b7f3fab8e0a29941aafe77e9c564c
-
C:\Users\Admin\AppData\Local\Temp\nsx4046.tmp\System.dllFilesize
11KB
MD5fccff8cb7a1067e23fd2e2b63971a8e1
SHA130e2a9e137c1223a78a0f7b0bf96a1c361976d91
SHA2566fcea34c8666b06368379c6c402b5321202c11b00889401c743fb96c516c679e
SHA512f4335e84e6f8d70e462a22f1c93d2998673a7616c868177cac3e8784a3be1d7d0bb96f2583fa0ed82f4f2b6b8f5d9b33521c279a42e055d80a94b4f3f1791e0c
-
memory/1828-8-0x0000000010000000-0x0000000010005000-memory.dmpFilesize
20KB
-
memory/1828-10-0x0000000010000000-0x0000000010005000-memory.dmpFilesize
20KB