Analysis

  • max time kernel
    120s
  • max time network
    121s
  • platform
    windows7_x64
  • resource
    win7-20231129-en
  • resource tags

    arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system
  • submitted
    29-06-2024 05:26

General

  • Target

    2024-06-29_2605d0980e8816862af5d327f1d7bb56_magniber.exe

  • Size

    12.2MB

  • MD5

    2605d0980e8816862af5d327f1d7bb56

  • SHA1

    1794dc936e40f2ee6a5f52b3dd851b4b88a3ce62

  • SHA256

    c02f13d8b6262ca0f663b37493f003a44125a300a8b617707c990db1dfe0fd3f

  • SHA512

    2f1b91e140cd9e32aefa6de1f38046ee7783e23d591586fdd43b3e7c1ceb46ae12c0218c38cb2b3be2be67241eca1650a765a874945f96c1be0794d5cb158755

  • SSDEEP

    196608:NPg2CWhGuZvjwQklner7/0S+6JfRbkebsN/cJ67DgKEl9sMvrrqNd2R7P:NYgGG7wFln+3fRb0V7El9s+rqNQP

Score
1/10

Malware Config

Signatures

  • Modifies registry class 3 IoCs
  • Modifies system certificate store 2 TTPs 10 IoCs
  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\2024-06-29_2605d0980e8816862af5d327f1d7bb56_magniber.exe
    "C:\Users\Admin\AppData\Local\Temp\2024-06-29_2605d0980e8816862af5d327f1d7bb56_magniber.exe"
    1⤵
    • Modifies registry class
    • Modifies system certificate store
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of SetWindowsHookEx
    PID:2232

Network

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
    Filesize

    70KB

    MD5

    49aebf8cbd62d92ac215b2923fb1b9f5

    SHA1

    1723be06719828dda65ad804298d0431f6aff976

    SHA256

    b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f

    SHA512

    bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0ACCF77CDCBFF39F6191887F6D2D357
    Filesize

    1KB

    MD5

    a266bb7dcc38a562631361bbf61dd11b

    SHA1

    3b1efd3a66ea28b16697394703a72ca340a05bd5

    SHA256

    df545bf919a2439c36983b54cdfc903dfa4f37d3996d8d84b4c31eec6f3c163e

    SHA512

    0da8ef4f8f6ed3d16d2bc8eb816b9e6e1345dfe2d91160196c47e6149a1d6aedaafadcefd66acdea7f72dcf0832770192ceac15b0c559c4ccc2c0e5581d5aefc

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    8d6c80469720a214a3d9b8e23abbb7e1

    SHA1

    d50df54b1c064e66912594b1d6261f42a522be61

    SHA256

    e04bfb0f9ac782175040b8364110da23850b6d750914676991bd1594afa8230f

    SHA512

    5bb67256470afdced93aef44640f5331ea2cb94f53854e4b2c19e01738b032ce4a3ad571836e7c7a270565b559db8cc6f9dca7e7f3be14613fe88603b8b48d47

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    3a9460aa6f4c0e57c7aa3d4dea8fe1fd

    SHA1

    ec6ccb2fc69193791453681662b710d560469efe

    SHA256

    4669131ee060fdff5f3413ad74e665b99763d091bd21ddbc3f32536c54ab52cb

    SHA512

    9b51c71cfa0ca7a65d5487094c69fb4de1afa86657522f1f8c2ba934eb1bc896452047fb1305235796a43472f129b14e91b5c1b9d36d177b7ff52acd171dc3bb

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0ACCF77CDCBFF39F6191887F6D2D357
    Filesize

    242B

    MD5

    1cbd79b813d0ba415b98f540481887e1

    SHA1

    810632ef7ba87c70f459db1e6e4ad623fbe6d54e

    SHA256

    398f6cd137cd5e92259c4b6b7ed62aa68c83a15ecaa18445cfccd40b9c90c879

    SHA512

    d2a98e475eb7f3179a2a23f3665e421704fa9b634665b34f830e67d1f61119bbcb1f2b6805d29ba9dd58e6ce5b90612b30771e137095da094e6e58633a123af8

  • C:\Users\Admin\AppData\Local\Temp\Tar1460.tmp
    Filesize

    181KB

    MD5

    4ea6026cf93ec6338144661bf1202cd1

    SHA1

    a1dec9044f750ad887935a01430bf49322fbdcb7

    SHA256

    8efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8

    SHA512

    6c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b