Analysis
-
max time kernel
141s -
max time network
126s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 05:38
Static task
static1
Behavioral task
behavioral1
Sample
c2a76268992490433ffcb33a12a05990b805a5058d42d19cb5c1aa3393d5c513.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
c2a76268992490433ffcb33a12a05990b805a5058d42d19cb5c1aa3393d5c513.exe
Resource
win10v2004-20240508-en
General
-
Target
c2a76268992490433ffcb33a12a05990b805a5058d42d19cb5c1aa3393d5c513.exe
-
Size
40KB
-
MD5
2254854a3f9d8a6fb28d157974b2e36a
-
SHA1
780ff05a19bfdf6611278b690e930c0f5b896e89
-
SHA256
c2a76268992490433ffcb33a12a05990b805a5058d42d19cb5c1aa3393d5c513
-
SHA512
eef246c85bea536d451138462a4b7619ca63b2970fc47fbd519fdfa2cdbbd0a287eaa097e510ce362d1e23eb6ea38b2465b6943475afc6f37aab9e488be4d7a8
-
SSDEEP
768:IMFV+Dj+RzO/86fEpYinAMxkla4Yi2laZAMxkEC:I00u8/VY7Hxax7YSx+
Malware Config
Extracted
cobaltstrike
http://45.76.97.68:3894/WwX7
-
user_agent
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Win64; x64; Trident/6.0; MATMJS)
Signatures
-
Cobaltstrike
Detected malicious payload which is part of Cobaltstrike.
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2068-0-0x0000000000020000-0x0000000000021000-memory.dmpFilesize
4KB
-
memory/2068-1-0x0000000004180000-0x0000000004580000-memory.dmpFilesize
4.0MB
-
memory/2068-2-0x0000000000390000-0x00000000003E6000-memory.dmpFilesize
344KB
-
memory/2068-3-0x0000000000400000-0x000000000040D000-memory.dmpFilesize
52KB
-
memory/2068-5-0x0000000000390000-0x00000000003E6000-memory.dmpFilesize
344KB