Overview
overview
3Static
static
1S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...ain.js
windows11-21h2-x64
3S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...ist.js
windows11-21h2-x64
3S$olaBma/t...ion.js
windows11-21h2-x64
3S$olaBma/t...ate.js
windows11-21h2-x64
3S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...les.js
windows11-21h2-x64
3S$olaBma/t...ain.js
windows11-21h2-x64
3S$olaBma/t...min.js
windows11-21h2-x64
3S$olaBma/t...ist.js
windows11-21h2-x64
3S$olaBma/t...gin.js
windows11-21h2-x64
3S$olaBma/t...ate.js
windows11-21h2-x64
3S$olaBma/t...jax.js
windows11-21h2-x64
3S$olaBma/t...ter.js
windows11-21h2-x64
3S$olaBma/t...oad.js
windows11-21h2-x64
3S$olaBma/t...pup.js
windows11-21h2-x64
3S$olaBma/t...ton.js
windows11-21h2-x64
3S$olaBma/t...nts.js
windows11-21h2-x64
3S$olaBma/t...lay.js
windows11-21h2-x64
3S$olaBma/t...opy.js
windows11-21h2-x64
3S$olaBma/t...orm.js
windows11-21h2-x64
3S$olaBma/t...ct.ps1
windows11-21h2-x64
3S$olaBma/t...nfo.js
windows11-21h2-x64
3S$olaBma/t...age.js
windows11-21h2-x64
3S$olaBma/t...ize.js
windows11-21h2-x64
3S$olaBma/t...mpl.js
windows11-21h2-x64
3S$olaBma/t...jax.js
windows11-21h2-x64
3S$olaBma/t...ide.js
windows11-21h2-x64
3S$olaBma/t...how.js
windows11-21h2-x64
3Analysis
-
max time kernel
210s -
max time network
276s -
platform
windows11-21h2_x64 -
resource
win11-20240611-en -
resource tags
arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system -
submitted
29-06-2024 04:59
Static task
static1
Behavioral task
behavioral1
Sample
S$olaBma/template/installation/assets/installation/dist/respond.min.js
Resource
win11-20240611-en
Behavioral task
behavioral2
Sample
S$olaBma/template/installation/assets/src/js/jquery.min.js
Resource
win11-20240508-en
Behavioral task
behavioral3
Sample
S$olaBma/template/installation/assets/src/js/main.js
Resource
win11-20240419-en
Behavioral task
behavioral4
Sample
S$olaBma/template/installation/assets/src/js/skel.min.js
Resource
win11-20240508-en
Behavioral task
behavioral5
Sample
S$olaBma/template/installation/assets_list.js
Resource
win11-20240508-en
Behavioral task
behavioral6
Sample
S$olaBma/template/installation/installation.js
Resource
win11-20240508-en
Behavioral task
behavioral7
Sample
S$olaBma/template/installation/template.js
Resource
win11-20240508-en
Behavioral task
behavioral8
Sample
S$olaBma/template/login/assets/src/js/combine/1_jquery.min.js
Resource
win11-20240611-en
Behavioral task
behavioral9
Sample
S$olaBma/template/login/assets/src/js/combine/2_bootstrap.min.js
Resource
win11-20240419-en
Behavioral task
behavioral10
Sample
S$olaBma/template/login/assets/src/js/combine/3_particles.js
Resource
win11-20240611-en
Behavioral task
behavioral11
Sample
S$olaBma/template/login/assets/src/js/combine/4_main.js
Resource
win11-20240611-en
Behavioral task
behavioral12
Sample
S$olaBma/template/login/assets/src/js/respond.min.js
Resource
win11-20240508-en
Behavioral task
behavioral13
Sample
S$olaBma/template/login/assets_list.js
Resource
win11-20240508-en
Behavioral task
behavioral14
Sample
S$olaBma/template/login/login.js
Resource
win11-20240508-en
Behavioral task
behavioral15
Sample
S$olaBma/template/template.js
Resource
win11-20240508-en
Behavioral task
behavioral16
Sample
S$olaBma/template/types/action/ajax.js
Resource
win11-20240611-en
Behavioral task
behavioral17
Sample
S$olaBma/template/types/action/fieldfilter.js
Resource
win11-20240508-en
Behavioral task
behavioral18
Sample
S$olaBma/template/types/action/file_upload.js
Resource
win11-20240611-en
Behavioral task
behavioral19
Sample
S$olaBma/template/types/action/popup.js
Resource
win11-20240419-en
Behavioral task
behavioral20
Sample
S$olaBma/template/types/button.js
Resource
win11-20240611-en
Behavioral task
behavioral21
Sample
S$olaBma/template/types/components.js
Resource
win11-20240611-en
Behavioral task
behavioral22
Sample
S$olaBma/template/types/display.js
Resource
win11-20240508-en
Behavioral task
behavioral23
Sample
S$olaBma/template/types/display/copy.js
Resource
win11-20240508-en
Behavioral task
behavioral24
Sample
S$olaBma/template/types/form.js
Resource
win11-20240611-en
Behavioral task
behavioral25
Sample
S$olaBma/template/types/form/select/select.ps1
Resource
win11-20240611-en
Behavioral task
behavioral26
Sample
S$olaBma/template/types/info.js
Resource
win11-20240508-en
Behavioral task
behavioral27
Sample
S$olaBma/template/types/page.js
Resource
win11-20240508-en
Behavioral task
behavioral28
Sample
S$olaBma/template/types/size.js
Resource
win11-20240611-en
Behavioral task
behavioral29
Sample
S$olaBma/template/types/tmpl.js
Resource
win11-20240508-en
Behavioral task
behavioral30
Sample
S$olaBma/template/types/tmpls/choose_ajax.js
Resource
win11-20240611-en
Behavioral task
behavioral31
Sample
S$olaBma/template/types/tmpls/choose_hide.js
Resource
win11-20240508-en
Behavioral task
behavioral32
Sample
S$olaBma/template/types/tmpls/choose_show.js
Resource
win11-20240508-en
General
-
Target
S$olaBma/template/types/form/select/select.ps1
-
Size
4KB
-
MD5
366862066aad093afa44604f1f98d7f7
-
SHA1
33e965ef247a8795b1f89f05c796273d11c265fb
-
SHA256
e2acfaa4aa4ba123b18eb839e5990513363744d3b635a65afbb86938ef58f667
-
SHA512
183b3a4470a9873ad48fda82fe3ea261f46fa08cb9bc8b0d554f4a0f028dcd3fc6f409afc555184e887ad11f0b36cbefa9185acf49b80c2c907595993fb8d39f
-
SSDEEP
96:rm3f6W4YbmNiiFESMtrfem94BTgO6VimnlSU+:yC39kmErtrfem94BTgOMO
Malware Config
Signatures
-
Suspicious behavior: EnumeratesProcesses 2 IoCs
Processes:
powershell.exepid process 744 powershell.exe 744 powershell.exe -
Suspicious use of AdjustPrivilegeToken 1 IoCs
Processes:
powershell.exedescription pid process Token: SeDebugPrivilege 744 powershell.exe
Processes
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe -ExecutionPolicy bypass -File C:\Users\Admin\AppData\Local\Temp\S$olaBma\template\types\form\select\select.ps11⤵
- Command and Scripting Interpreter: PowerShell
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_qkc55qqf.0fd.ps1Filesize
60B
MD5d17fe0a3f47be24a6453e9ef58c94641
SHA16ab83620379fc69f80c0242105ddffd7d98d5d9d
SHA25696ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
SHA5125b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82
-
memory/744-0-0x00007FF935E93000-0x00007FF935E95000-memory.dmpFilesize
8KB
-
memory/744-9-0x00000222BAAD0000-0x00000222BAAF2000-memory.dmpFilesize
136KB
-
memory/744-10-0x00007FF935E90000-0x00007FF936952000-memory.dmpFilesize
10.8MB
-
memory/744-11-0x00007FF935E90000-0x00007FF936952000-memory.dmpFilesize
10.8MB
-
memory/744-12-0x00007FF935E90000-0x00007FF936952000-memory.dmpFilesize
10.8MB
-
memory/744-15-0x00007FF935E90000-0x00007FF936952000-memory.dmpFilesize
10.8MB