Analysis

  • max time kernel
    149s
  • max time network
    150s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    28-06-2024 10:25

General

  • Target

    d5417a22f68d01a223f985ced38b9793f7459d8cf1ff8bd03c8a9352a2620f2b.exe

  • Size

    19KB

  • MD5

    78b8ec331f2e89994661fc0adc5676d8

  • SHA1

    043498ec2241aa715a3293d4bf138f58f81dd8a5

  • SHA256

    d5417a22f68d01a223f985ced38b9793f7459d8cf1ff8bd03c8a9352a2620f2b

  • SHA512

    db4f1ebacef0fe566f80ad831acb05e67ca10bd1a4bd50166fb1af93cec3a505d3ee2ca20b0bf64b2546b500ba047dcc440f27090651a970889544c7e264c00e

  • SSDEEP

    192:1PV7qaCF6Op1t2dobVXujRDcBaXWQjwOT/2KeBmOUWF8qa1Dojjgi:1JqaCF31cix+Dc4zjZeMOhFF46gi

Malware Config

Extracted

Family

cobaltstrike

C2

http://172.16.7.81:80/w1hM

Attributes
  • user_agent

    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; InfoPath.2)

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\d5417a22f68d01a223f985ced38b9793f7459d8cf1ff8bd03c8a9352a2620f2b.exe
    "C:\Users\Admin\AppData\Local\Temp\d5417a22f68d01a223f985ced38b9793f7459d8cf1ff8bd03c8a9352a2620f2b.exe"
    1⤵
      PID:2856

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2856-0-0x0000000000020000-0x0000000000021000-memory.dmp
      Filesize

      4KB

    • memory/2856-1-0x0000000000400000-0x000000000040C000-memory.dmp
      Filesize

      48KB