Overview
overview
10Static
static
3windows-ma...00.exe
windows7-x64
windows-ma...00.exe
windows10-2004-x64
windows-ma...fy.exe
windows7-x64
8windows-ma...fy.exe
windows10-2004-x64
8windows-ma...or.exe
windows7-x64
windows-ma...or.exe
windows10-2004-x64
windows-ma...XT.vbs
windows7-x64
1windows-ma...XT.vbs
windows10-2004-x64
1windows-ma...ck.exe
windows7-x64
6windows-ma...ck.exe
windows10-2004-x64
7windows-ma....0.exe
windows7-x64
windows-ma....0.exe
windows10-2004-x64
windows-ma...p).exe
windows7-x64
10windows-ma...p).exe
windows10-2004-x64
Analysis
-
max time kernel
22s -
max time network
40s -
platform
windows10-2004_x64 -
resource
win10v2004-20240226-en -
resource tags
arch:x64arch:x86image:win10v2004-20240226-enlocale:en-usos:windows10-2004-x64system -
submitted
29-06-2024 05:26
Static task
static1
Behavioral task
behavioral1
Sample
windows-malware-master/000/000.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
windows-malware-master/000/000.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
windows-malware-master/Bonzify/Bonzify.exe
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
windows-malware-master/Bonzify/Bonzify.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
windows-malware-master/BossDaMajor/BossDaMajor.exe
Resource
win7-20240611-en
Behavioral task
behavioral6
Sample
windows-malware-master/BossDaMajor/BossDaMajor.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
windows-malware-master/ILOVEYOU/LOVE-LETTER-FOR-YOU.TXT.vbs
Resource
win7-20240419-en
Behavioral task
behavioral8
Sample
windows-malware-master/ILOVEYOU/LOVE-LETTER-FOR-YOU.TXT.vbs
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
windows-malware-master/MEMZ/geometry dash auto speedhack.exe
Resource
win7-20240611-en
Behavioral task
behavioral10
Sample
windows-malware-master/MEMZ/geometry dash auto speedhack.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral11
Sample
windows-malware-master/MrsMajor 2.0/MrsMajor2.0.exe
Resource
win7-20240221-en
Behavioral task
behavioral12
Sample
windows-malware-master/MrsMajor 2.0/MrsMajor2.0.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
windows-malware-master/WinXP Horror Edition/WinXP.Horror.Destructive (Created By WobbyChip).exe
Resource
win7-20240508-en
Behavioral task
behavioral14
Sample
windows-malware-master/WinXP Horror Edition/WinXP.Horror.Destructive (Created By WobbyChip).exe
Resource
win10v2004-20240508-en
General
-
Target
windows-malware-master/MEMZ/geometry dash auto speedhack.exe
-
Size
14KB
-
MD5
19dbec50735b5f2a72d4199c4e184960
-
SHA1
6fed7732f7cb6f59743795b2ab154a3676f4c822
-
SHA256
a3d5715a81f2fbeb5f76c88c9c21eeee87142909716472f911ff6950c790c24d
-
SHA512
aa8a6bbb1ec516d5d5acf8be6863a4c6c5d754cee12b3d374c3a6acb393376806edc422f0ffb661c210e5b9485da88521e4a0956a4b7b08a5467cfaacd90591d
-
SSDEEP
192:sIvxdXSQeWSg9JJS/lcIEiwqZKBkDFR43xWTM3LHn8f26gyr6yfFCj3r:sMVSaSEglcIqq3agmLc+6gyWqFCj
Malware Config
Signatures
-
Checks computer location settings 2 TTPs 1 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
geometry dash auto speedhack.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-3808065738-1666277613-1125846146-1000\Control Panel\International\Geo\Nation geometry dash auto speedhack.exe -
Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs
Bootkits write to the MBR to gain persistence at a level below the operating system.
Processes:
geometry dash auto speedhack.exedescription ioc process File opened for modification \??\PhysicalDrive0 geometry dash auto speedhack.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
geometry dash auto speedhack.exegeometry dash auto speedhack.exegeometry dash auto speedhack.exegeometry dash auto speedhack.exegeometry dash auto speedhack.exepid process 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 3400 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 1420 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe 1308 geometry dash auto speedhack.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
geometry dash auto speedhack.exegeometry dash auto speedhack.exegeometry dash auto speedhack.exepid process 4544 geometry dash auto speedhack.exe 3452 geometry dash auto speedhack.exe 4440 geometry dash auto speedhack.exe -
Suspicious use of WriteProcessMemory 18 IoCs
Processes:
geometry dash auto speedhack.exedescription pid process target process PID 4752 wrote to memory of 3452 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 3452 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 3452 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 3400 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 3400 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 3400 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1420 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1420 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1420 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1308 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1308 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 1308 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4440 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4440 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4440 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4544 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4544 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe PID 4752 wrote to memory of 4544 4752 geometry dash auto speedhack.exe geometry dash auto speedhack.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"1⤵
- Checks computer location settings
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /watchdog2⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of SetWindowsHookEx
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /watchdog2⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /watchdog2⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /watchdog2⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /watchdog2⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of SetWindowsHookEx
-
C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe"C:\Users\Admin\AppData\Local\Temp\windows-malware-master\MEMZ\geometry dash auto speedhack.exe" /main2⤵
- Writes to the Master Boot Record (MBR)
- Suspicious use of SetWindowsHookEx
-
C:\Windows\SysWOW64\notepad.exe"C:\Windows\System32\notepad.exe" \note.txt3⤵