Analysis

  • max time kernel
    133s
  • max time network
    127s
  • platform
    windows7_x64
  • resource
    win7-20240220-en
  • resource tags

    arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system
  • submitted
    28-06-2024 12:46

General

  • Target

    Data/Nav1/DH1.htm

  • Size

    5KB

  • MD5

    3e9756a6b25dc62fde3b0d75a406e958

  • SHA1

    992a6a34e84a08434cb06c77a26bce478d3bab84

  • SHA256

    0327b1f790dd0b5469e186bb679e3228a9489509e5780fae49f07a8cc9622505

  • SHA512

    326743f04e3b63391c0cc14d75ee292c3d28406d7577f319f0d2dff6ec554b7e76a8d4c0b9b69a115d619290adc3c7917be1d5fa1cab832796ad151040bbf281

  • SSDEEP

    96:ucQgITXjytvQaxxRAfmWz/PZ3w+FQVZAiMhqABwLmFFgH2a:ucJkutpIz/PZ/P2Oa

Score
1/10

Malware Config

Signatures

  • Modifies Internet Explorer settings 1 TTPs 41 IoCs
  • Suspicious use of FindShellTrayWindow 1 IoCs
  • Suspicious use of SetWindowsHookEx 6 IoCs
  • Suspicious use of WriteProcessMemory 4 IoCs

Processes

  • C:\Program Files\Internet Explorer\iexplore.exe
    "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\Admin\AppData\Local\Temp\Data\Nav1\DH1.htm
    1⤵
    • Modifies Internet Explorer settings
    • Suspicious use of FindShellTrayWindow
    • Suspicious use of SetWindowsHookEx
    • Suspicious use of WriteProcessMemory
    PID:2192
    • C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
      "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2192 CREDAT:275457 /prefetch:2
      2⤵
      • Modifies Internet Explorer settings
      • Suspicious use of SetWindowsHookEx
      PID:2960

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
    Filesize

    70KB

    MD5

    49aebf8cbd62d92ac215b2923fb1b9f5

    SHA1

    1723be06719828dda65ad804298d0431f6aff976

    SHA256

    b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f

    SHA512

    bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    be5fc86fd26ebb596061ef697b39e8bd

    SHA1

    e7c3791ad6a64c3c98e0aa9bc26801266626b18f

    SHA256

    3b983b23f1d09b16743d6f51ca1ce4c72690dce2ee9f73d6fb8f14f6894013f6

    SHA512

    9613e4255a593bec7135e6c52a667bd6dc1264c550cb1be5782926adb34f379de705f4ba77f2ac5bf18eb6a564ee78b63882fc0c9b4c700dce2ac621311e79e2

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    5ca2d6396cb8d434e336debf64deb98f

    SHA1

    491dd165c73d8b40c4ca68efee07d0620db1bc2b

    SHA256

    b17d7c0db542f79b6c013c31c246575f705aed4deff4fe07720babc5b9be121a

    SHA512

    a876b30f18e0bfa20f2c61decba959bfdd07532f17466d0e6dbca9f43ceed290291bf70c28d0a4ced1a89eeaf97faff3e2fe22708f6fc0cac86c6cfd85ccd532

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    6a4b3d33b888f2bc91eca5edf8df86a3

    SHA1

    94294f3210abd0cbcbe061dbc80d10359a28a7b2

    SHA256

    81f9d23635d6fd7ec6523be9a8af01d9c0bf7021cea123db459a73643484aa6b

    SHA512

    adc5f1c397f7df1f6c322ac7ac58a37756505627fe5b83fbce12609e9899ac4b06c71ee38fce68e678281a79423daf2c64bd7f210e180f3663cd097afb7bc2f0

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    d28cf91d9b1bef7538c004bee3e3780b

    SHA1

    b6b148f6f4b8c430d68ebd3bb5009ce0ce796cd5

    SHA256

    222fb846e6751ea18431920701835a3a7dd089d1c178cf2e5de6076843248727

    SHA512

    807283d602952c5eab3f60faa1ba329f8a976b9cc2871acd3bafe08f7231746178a21976d5e513bc14c1eb5c117274338d8e2031dba72bb56e5b63de507dfe05

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    2e241ca13fbfbdc6a0b28bdc3ed09125

    SHA1

    6006a5dc639a810dd0a0f53907d7b5f39c630a85

    SHA256

    553ad591504b47ece57b1a0a9e3d5e85b904fa22292945ca26ef39f7d7257794

    SHA512

    2de9dd50a298e4a5139a2572adf1034ad1557ec39f18fe2f1e34be045910b01136b6237c64e1c38b30cefb24e773be7b4d89a198edc3c78cfff3248bb15e6a75

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    99209ff4e4b100518159842187f46ced

    SHA1

    ede5c7bbb74b36acc77cf1bff9ce3502ed597f6c

    SHA256

    35d474b604e48ea06de461a77b7f3a595f58c42b65f68c9f9ac436b10b0172f9

    SHA512

    1ecb6b43f82120443e98ff314d9f4c747fcbe35373319b9e4b2061eb303e2167c1c877c0532898269885b4247e6115b9bbb39a9289904e9aca097e6cd7adfe20

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    0c131d4fd9624e520e00f7f418a1faef

    SHA1

    63094406fc946d04d37929f6f7f0d279c1979a8e

    SHA256

    9a230ca701ff843255c2a416dc76fab510882989f2651a1a663c572a0b9381b7

    SHA512

    fa6ec2439b8089d68486d8dd2201ec406a2c4a65c708c1028f3923d34ca5dae5a44d3cfede42d37a4708865f759937311c235e50eb14fe1971302f93e9eab999

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    e58aa44e9ff87b80ec88a5616f8e447b

    SHA1

    bd61503c814596354f544be544103f8a098fea4e

    SHA256

    9b2cd520818b3407fecce8f1576f6afe91605157ce55525bd52d116127f99482

    SHA512

    ba9c06fba711f9c897e9b1b97e055a1f5757cae6db1f61e8dd086aaf3e95101e6349b427bc14244db0b843d5b4cf4dbca09e549550a20a05304bd107b1ace1a5

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    d08faee190d90cf30ef3b76fbf04ab5a

    SHA1

    aed28139633a2fbcacddbcfbcf2a5a771184a2ba

    SHA256

    875f89d70121f07bcac0fb014f0fb13098ae3fb8f03f9b540550873bcbaec0ad

    SHA512

    3d1d9b8c78f9e60219860b497b22ef148b702178b019e577863c91eadb28db35075b1bf34887134b22e9ff281917b26cd971b4e0610468c8519c425e5fdc330f

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    2f49767d89e428b09627dd53bef73e52

    SHA1

    530cd841b0e56942d3f93f4efefb887cb40d3ea5

    SHA256

    1a2344650d4d4d9bd58662ee52a6947b1432d243b0eb130b28e454668a2c472e

    SHA512

    b2027e26bc8972879ec8047ded150ba57be1f9563d8c128096231c9b06f78c5f827a371304fc43ffc4bbac5a5d2621a020a365e06925e7ec4fc36b05b908f76f

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    56d0da33fa5e568f15a82c0af03609a9

    SHA1

    9977edc74700bc1d8c541e6eb419bfd8ac35de9a

    SHA256

    a912fee80f43abbbe060ee9b805b7f42f3b0a423af0957068edef7d2d7b6ba43

    SHA512

    08eee3b5ea7ab4d182e7a750713adce6b8c3b1270f6bafc1c04469361b3117799638e338e62fe1729b61675c377d8e1221be419b2d0507da30f9a2a3479932e1

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    6a8327ff747e721456be083420945b68

    SHA1

    b099cdb238d712314f03bc48939084b0aeddd889

    SHA256

    f143989671dfd1a0f31a89c3d2054d35fe47b4c29ff8a4ab026d64eec4325416

    SHA512

    d0ac9ac9f9d06f7514aac396a967f325543991272d50c2579248ed43fcfacd17bbf8f1edcf22b88fedacd56be2bf810ef31e192f754d7557ececac43aeff36aa

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    4854c4e1770e0ae14279bf497549f656

    SHA1

    c251ffa55a37b1ede12a019a33383052d9e1db58

    SHA256

    1b1e43be53fb95af89435ea9bce33ba0112d6dfc8a7be18ac9ebd53d1b5ef5a3

    SHA512

    43b1208a784898059ca2231c44fcdf862a27d86ebff759411ebbd05c91b419bfe3179f30689f986e2d488783b732cb1c790f69b9ee6ef592f320a439754c6137

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    30dd60ec9de01aaf463e5b82800ac49f

    SHA1

    42dcbb08c5b3b96fc3eaf9a530726f693de10e81

    SHA256

    5d17f605331dee431ac5ed6417b8b07dd4f37a5666a15876b2de49f1903141a0

    SHA512

    f1f122f0c3b08f6e84d5ad84a4524ae814709f32a0eea012b9411d67a521b6a1a0d64168343a89379961e2ac0e74b8b2cf897554eb82072e04f64c5048f21a74

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    65d1c73c860d08cfdb96018c1ea5f6fc

    SHA1

    91884f74b4c32dd6ded462d90c5924fc24a41be2

    SHA256

    4cfd624b990274b32c9afe6f3debd425824b7e2d05060f5df9c592e4ce120803

    SHA512

    449ec51a32746eaa4f55754ea42621c6ddcb185beb7a5b34b0d5ed18f8a8f45d3fd2760632cc0cdeca853bde643f4760f7ad4c715e56e2d98d3d22278f1664fe

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    3806f77b8c56e5e627e215ce2a1e9350

    SHA1

    31ecba505265c75d17da5c87e40ee719f0408323

    SHA256

    efa6510e0f25b45cfd93eafe1f9753e7cd09e4e5f11450d0e5393614c363bc4e

    SHA512

    48cc283399d8b45800fb894044fae3fe54e1ec418b27c29fc591cbd4f9fda23b83419ef7d9988869624533231278dbb4b00fd0177ca035e2da345e19c78bb360

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    e1f626aedcbfa3e233056cb88c88af8b

    SHA1

    17441f0a4501662170e22820457f7178a7e24789

    SHA256

    730d19db0007a183b3ae36065f8dc1ee6d9dda2eedb9079144281e240ac6a3ae

    SHA512

    1a74c79d2ed2faddc5553335387d493930bc5fa5d3cce411844f49c03fcb4c1194c88effca6ec6cac9398e7a3b010db17328acb72de86ac3ff51be8fb473a663

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    cafd90d30d77bd9c1d0757664605d8fc

    SHA1

    b524fd872d6a7df711b0a3eaac87adb7b3958f48

    SHA256

    b0b5aaf483ee2f4e1fd7770ef0de74a5a34c6afa0c347527b3872c3c1dd1c544

    SHA512

    1ba7bc0c4714143383a2abb46816d9bf80c37e813e8fa120e0ceb7895ffb1bac72343041c7ff7754d996a9a7463a956a9af8d125898191f6b17f6274833d2f54

  • C:\Users\Admin\AppData\Local\Temp\Cab2D68.tmp
    Filesize

    65KB

    MD5

    ac05d27423a85adc1622c714f2cb6184

    SHA1

    b0fe2b1abddb97837ea0195be70ab2ff14d43198

    SHA256

    c6456e12e5e53287a547af4103e0397cb9697e466cf75844312dc296d43d144d

    SHA512

    6d0ef9050e41fbae680e0e59dd0f90b6ac7fea5579ef5708b69d5da33a0ece7e8b16574b58b17b64a34cc34a4ffc22b4a62c1ece61f36c4a11a0665e0536b90d

  • C:\Users\Admin\AppData\Local\Temp\Tar2E4B.tmp
    Filesize

    181KB

    MD5

    4ea6026cf93ec6338144661bf1202cd1

    SHA1

    a1dec9044f750ad887935a01430bf49322fbdcb7

    SHA256

    8efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8

    SHA512

    6c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b