Analysis
-
max time kernel
148s -
max time network
120s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 03:05
Static task
static1
Behavioral task
behavioral1
Sample
pay09809988.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
pay09809988.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/System.dll
Resource
win7-20240419-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/System.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
jy2091qep.dll
Resource
win7-20240220-en
Behavioral task
behavioral6
Sample
jy2091qep.dll
Resource
win10v2004-20240226-en
General
-
Target
pay09809988.exe
-
Size
452KB
-
MD5
dc83500f11eef58ddbb21c9dd2d17729
-
SHA1
46b0de105332e090806d5e95f38ee0a33c10ad3b
-
SHA256
2160a2fba2efc22751b82cebb9d4ce21dfe35782cfb21bbf512687f413b80e65
-
SHA512
b1289ae61523b0e170a434361e727bf5e0e0043c4596214b4823e6c961ace6a61b796adcbd459cbdcddab3c7d9ff3236ad81a9d88f8a9ca31206a90fb1c127ad
-
SSDEEP
12288:RH06XwKIhiXX1oJMdqvEu6XFhCQxy1Hex/pKAQb9NsAm:9frX1oJwqvEujh2xiBm
Malware Config
Signatures
-
Loads dropped DLL 64 IoCs
Processes:
pay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepid process 2184 pay09809988.exe 2184 pay09809988.exe 1976 pay09809988.exe 1976 pay09809988.exe 2836 pay09809988.exe 2836 pay09809988.exe 2752 pay09809988.exe 2752 pay09809988.exe 1424 pay09809988.exe 1424 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 2564 pay09809988.exe 2564 pay09809988.exe 944 pay09809988.exe 944 pay09809988.exe 2616 pay09809988.exe 2616 pay09809988.exe 1780 pay09809988.exe 1780 pay09809988.exe 3036 pay09809988.exe 3036 pay09809988.exe 700 pay09809988.exe 700 pay09809988.exe 560 pay09809988.exe 560 pay09809988.exe 2464 pay09809988.exe 2464 pay09809988.exe 1604 pay09809988.exe 1604 pay09809988.exe 2660 pay09809988.exe 2660 pay09809988.exe 2024 pay09809988.exe 2024 pay09809988.exe 1616 pay09809988.exe 1616 pay09809988.exe 1184 pay09809988.exe 1184 pay09809988.exe 2832 pay09809988.exe 2832 pay09809988.exe 3008 pay09809988.exe 3008 pay09809988.exe 2768 pay09809988.exe 2768 pay09809988.exe 2656 pay09809988.exe 2656 pay09809988.exe 1700 pay09809988.exe 1700 pay09809988.exe 3068 pay09809988.exe 3068 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 1584 pay09809988.exe 1584 pay09809988.exe 2916 pay09809988.exe 2916 pay09809988.exe 1560 pay09809988.exe 1560 pay09809988.exe 2236 pay09809988.exe 2236 pay09809988.exe 2536 pay09809988.exe 2536 pay09809988.exe 600 pay09809988.exe 600 pay09809988.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
pay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepid process 2184 pay09809988.exe 2184 pay09809988.exe 2184 pay09809988.exe 2184 pay09809988.exe 1976 pay09809988.exe 1976 pay09809988.exe 1976 pay09809988.exe 1976 pay09809988.exe 2836 pay09809988.exe 2836 pay09809988.exe 2836 pay09809988.exe 2836 pay09809988.exe 2752 pay09809988.exe 2752 pay09809988.exe 2752 pay09809988.exe 2752 pay09809988.exe 1424 pay09809988.exe 1424 pay09809988.exe 1424 pay09809988.exe 1424 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 2564 pay09809988.exe 2564 pay09809988.exe 2564 pay09809988.exe 2564 pay09809988.exe 944 pay09809988.exe 944 pay09809988.exe 944 pay09809988.exe 944 pay09809988.exe 2616 pay09809988.exe 2616 pay09809988.exe 2616 pay09809988.exe 2616 pay09809988.exe 1780 pay09809988.exe 1780 pay09809988.exe 1780 pay09809988.exe 1780 pay09809988.exe 3036 pay09809988.exe 3036 pay09809988.exe 3036 pay09809988.exe 3036 pay09809988.exe 700 pay09809988.exe 700 pay09809988.exe 700 pay09809988.exe 700 pay09809988.exe 560 pay09809988.exe 560 pay09809988.exe 560 pay09809988.exe 560 pay09809988.exe 2464 pay09809988.exe 2464 pay09809988.exe 2464 pay09809988.exe 2464 pay09809988.exe 1604 pay09809988.exe 1604 pay09809988.exe 1604 pay09809988.exe 1604 pay09809988.exe 2660 pay09809988.exe 2660 pay09809988.exe 2660 pay09809988.exe 2660 pay09809988.exe -
Suspicious behavior: MapViewOfSection 60 IoCs
Processes:
pay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepid process 2184 pay09809988.exe 1976 pay09809988.exe 2836 pay09809988.exe 2836 pay09809988.exe 2752 pay09809988.exe 1424 pay09809988.exe 2940 pay09809988.exe 2564 pay09809988.exe 2564 pay09809988.exe 944 pay09809988.exe 2616 pay09809988.exe 1780 pay09809988.exe 1780 pay09809988.exe 3036 pay09809988.exe 700 pay09809988.exe 560 pay09809988.exe 2464 pay09809988.exe 1604 pay09809988.exe 2660 pay09809988.exe 2660 pay09809988.exe 2024 pay09809988.exe 1616 pay09809988.exe 1184 pay09809988.exe 2832 pay09809988.exe 3008 pay09809988.exe 3008 pay09809988.exe 2768 pay09809988.exe 2656 pay09809988.exe 1700 pay09809988.exe 3068 pay09809988.exe 2940 pay09809988.exe 2940 pay09809988.exe 1584 pay09809988.exe 2916 pay09809988.exe 1560 pay09809988.exe 2236 pay09809988.exe 2536 pay09809988.exe 600 pay09809988.exe 1484 pay09809988.exe 1484 pay09809988.exe 408 pay09809988.exe 1712 pay09809988.exe 2464 pay09809988.exe 988 pay09809988.exe 2264 pay09809988.exe 1752 pay09809988.exe 2724 pay09809988.exe 2732 pay09809988.exe 2732 pay09809988.exe 2168 pay09809988.exe 2168 pay09809988.exe 2604 pay09809988.exe 2596 pay09809988.exe 2768 pay09809988.exe 2360 pay09809988.exe 2360 pay09809988.exe 1424 pay09809988.exe 2136 pay09809988.exe 2956 pay09809988.exe 2956 pay09809988.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
pay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exepay09809988.exedescription pid process target process PID 2184 wrote to memory of 2424 2184 pay09809988.exe MSBuild.exe PID 2184 wrote to memory of 2424 2184 pay09809988.exe MSBuild.exe PID 2184 wrote to memory of 2424 2184 pay09809988.exe MSBuild.exe PID 2184 wrote to memory of 2424 2184 pay09809988.exe MSBuild.exe PID 2184 wrote to memory of 2424 2184 pay09809988.exe MSBuild.exe PID 2184 wrote to memory of 1976 2184 pay09809988.exe pay09809988.exe PID 2184 wrote to memory of 1976 2184 pay09809988.exe pay09809988.exe PID 2184 wrote to memory of 1976 2184 pay09809988.exe pay09809988.exe PID 2184 wrote to memory of 1976 2184 pay09809988.exe pay09809988.exe PID 1976 wrote to memory of 2880 1976 pay09809988.exe MSBuild.exe PID 1976 wrote to memory of 2880 1976 pay09809988.exe MSBuild.exe PID 1976 wrote to memory of 2880 1976 pay09809988.exe MSBuild.exe PID 1976 wrote to memory of 2880 1976 pay09809988.exe MSBuild.exe PID 1976 wrote to memory of 2880 1976 pay09809988.exe MSBuild.exe PID 1976 wrote to memory of 2836 1976 pay09809988.exe pay09809988.exe PID 1976 wrote to memory of 2836 1976 pay09809988.exe pay09809988.exe PID 1976 wrote to memory of 2836 1976 pay09809988.exe pay09809988.exe PID 1976 wrote to memory of 2836 1976 pay09809988.exe pay09809988.exe PID 2836 wrote to memory of 1316 2836 pay09809988.exe MSBuild.exe PID 2836 wrote to memory of 1316 2836 pay09809988.exe MSBuild.exe PID 2836 wrote to memory of 1316 2836 pay09809988.exe MSBuild.exe PID 2836 wrote to memory of 1316 2836 pay09809988.exe MSBuild.exe PID 2836 wrote to memory of 1316 2836 pay09809988.exe MSBuild.exe PID 2836 wrote to memory of 2752 2836 pay09809988.exe pay09809988.exe PID 2836 wrote to memory of 2752 2836 pay09809988.exe pay09809988.exe PID 2836 wrote to memory of 2752 2836 pay09809988.exe pay09809988.exe PID 2836 wrote to memory of 2752 2836 pay09809988.exe pay09809988.exe PID 2752 wrote to memory of 2652 2752 pay09809988.exe MSBuild.exe PID 2752 wrote to memory of 2652 2752 pay09809988.exe MSBuild.exe PID 2752 wrote to memory of 2652 2752 pay09809988.exe MSBuild.exe PID 2752 wrote to memory of 2652 2752 pay09809988.exe MSBuild.exe PID 2752 wrote to memory of 2652 2752 pay09809988.exe MSBuild.exe PID 2752 wrote to memory of 1424 2752 pay09809988.exe pay09809988.exe PID 2752 wrote to memory of 1424 2752 pay09809988.exe pay09809988.exe PID 2752 wrote to memory of 1424 2752 pay09809988.exe pay09809988.exe PID 2752 wrote to memory of 1424 2752 pay09809988.exe pay09809988.exe PID 1424 wrote to memory of 2976 1424 pay09809988.exe MSBuild.exe PID 1424 wrote to memory of 2976 1424 pay09809988.exe MSBuild.exe PID 1424 wrote to memory of 2976 1424 pay09809988.exe MSBuild.exe PID 1424 wrote to memory of 2976 1424 pay09809988.exe MSBuild.exe PID 1424 wrote to memory of 2976 1424 pay09809988.exe MSBuild.exe PID 1424 wrote to memory of 2940 1424 pay09809988.exe pay09809988.exe PID 1424 wrote to memory of 2940 1424 pay09809988.exe pay09809988.exe PID 1424 wrote to memory of 2940 1424 pay09809988.exe pay09809988.exe PID 1424 wrote to memory of 2940 1424 pay09809988.exe pay09809988.exe PID 2940 wrote to memory of 2140 2940 pay09809988.exe MSBuild.exe PID 2940 wrote to memory of 2140 2940 pay09809988.exe MSBuild.exe PID 2940 wrote to memory of 2140 2940 pay09809988.exe MSBuild.exe PID 2940 wrote to memory of 2140 2940 pay09809988.exe MSBuild.exe PID 2940 wrote to memory of 2140 2940 pay09809988.exe MSBuild.exe PID 2940 wrote to memory of 2564 2940 pay09809988.exe pay09809988.exe PID 2940 wrote to memory of 2564 2940 pay09809988.exe pay09809988.exe PID 2940 wrote to memory of 2564 2940 pay09809988.exe pay09809988.exe PID 2940 wrote to memory of 2564 2940 pay09809988.exe pay09809988.exe PID 2564 wrote to memory of 708 2564 pay09809988.exe MSBuild.exe PID 2564 wrote to memory of 708 2564 pay09809988.exe MSBuild.exe PID 2564 wrote to memory of 708 2564 pay09809988.exe MSBuild.exe PID 2564 wrote to memory of 708 2564 pay09809988.exe MSBuild.exe PID 2564 wrote to memory of 708 2564 pay09809988.exe MSBuild.exe PID 2564 wrote to memory of 944 2564 pay09809988.exe pay09809988.exe PID 2564 wrote to memory of 944 2564 pay09809988.exe pay09809988.exe PID 2564 wrote to memory of 944 2564 pay09809988.exe pay09809988.exe PID 2564 wrote to memory of 944 2564 pay09809988.exe pay09809988.exe PID 944 wrote to memory of 2788 944 pay09809988.exe MSBuild.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"1⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"2⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"3⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"3⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"4⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"4⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"5⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"5⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"6⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"6⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"7⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"7⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"8⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"8⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"9⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"9⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"10⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"10⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"11⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"11⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"12⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"12⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"13⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"13⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"14⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"14⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"15⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"15⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"16⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"16⤵
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"17⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"17⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"18⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"18⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"19⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"19⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"20⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"20⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"21⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"21⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"22⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"22⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"23⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"23⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"24⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"24⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"25⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"25⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"26⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"26⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"27⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"27⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"28⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"28⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"29⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"29⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"30⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"30⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"31⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"31⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"32⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"32⤵
- Loads dropped DLL
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"33⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"33⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"34⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"34⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"35⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"35⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"36⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"36⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"37⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"37⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"38⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"38⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"39⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"39⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"40⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"40⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"41⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"41⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"42⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"42⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"43⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"43⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"44⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"44⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"45⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"45⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"46⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"46⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"47⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"47⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"48⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"48⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"49⤵
-
C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"49⤵
- Suspicious behavior: MapViewOfSection
-
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Users\Admin\AppData\Local\Temp\pay09809988.exe"50⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\mybuttxxxt.xffFilesize
395KB
MD5fab8080f79362b1ee8439686b6362c81
SHA1051216d918734d447a11c92dc1df297bab7fc9f9
SHA25609ca4092c88681c26d4ef899333913d078e9bd33c5ff86d4ae245c67f5361ddf
SHA512c2247e2e5793207be1f1d8e9343894c25f9f74ec7b9e59bd5c62dc2ebfb2d9e145ab6fef2e9c817843d074f0cc78c594c21cd1ea390eb40b6d7ef3e4d725ad5f
-
\Users\Admin\AppData\Local\Temp\jy2091qep.dllFilesize
18KB
MD5a393df2af4708ff2592687ff4ee343b9
SHA119b5212fc5dbd673f7e4f78c52b6c0ea33121d85
SHA256eea2ac27c7db126176b9cbf245328c9acb06665995f1212cc28792304ca3f6f5
SHA512b960e1ad593a17d94cacec2ef4e30c1b17b69469e3f1a0b26d992dce1ef697078a466bd1bde5779373bae6ff5b35c39a13f818c03c4a3a3eacda051b44ea0491
-
\Users\Admin\AppData\Local\Temp\nsy18CF.tmp\System.dllFilesize
11KB
MD5fccff8cb7a1067e23fd2e2b63971a8e1
SHA130e2a9e137c1223a78a0f7b0bf96a1c361976d91
SHA2566fcea34c8666b06368379c6c402b5321202c11b00889401c743fb96c516c679e
SHA512f4335e84e6f8d70e462a22f1c93d2998673a7616c868177cac3e8784a3be1d7d0bb96f2583fa0ed82f4f2b6b8f5d9b33521c279a42e055d80a94b4f3f1791e0c
-
memory/1560-332-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/1976-26-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2184-11-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2184-12-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2264-415-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2264-414-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2564-95-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2604-461-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2752-55-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2836-41-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB
-
memory/2836-40-0x0000000010000000-0x0000000010007000-memory.dmpFilesize
28KB