Overview
overview
10Static
static
3net6.0-windows.zip
windows10-2004-x64
10assets/fon...ug.zip
windows10-2004-x64
1assets/fonts/kust.ttf
windows10-2004-x64
7assets/fon...11.txt
windows10-2004-x64
1assets/fon...ks.ttf
windows10-2004-x64
7assets/fon...ot.otf
windows10-2004-x64
7assets/fon...85.ttf
windows10-2004-x64
7assets/fon...la.txt
windows10-2004-x64
1assets/mod...ra.mdl
windows10-2004-x64
3assets/mod...r.json
windows10-2004-x64
3assets/mod...t.json
windows10-2004-x64
3assets/mod...r.json
windows10-2004-x64
3assets/mod...r.json
windows10-2004-x64
3assets/mod...r.json
windows10-2004-x64
3assets/mod...t.json
windows10-2004-x64
3mfccpu.dll
windows10-2004-x64
1picker.dll
windows10-2004-x64
1ref/MagicO...r1.exe
windows10-2004-x64
1releases.exe
windows10-2004-x64
10skin/Color...er.png
windows10-2004-x64
3skin/Color...al.png
windows10-2004-x64
3skin/Color...er.png
windows10-2004-x64
3skin/Color...al.png
windows10-2004-x64
3skin/color...er.png
windows10-2004-x64
3skin/color...al.png
windows10-2004-x64
3skin/color...mbs.db
windows10-2004-x64
3skin/color...er.png
windows10-2004-x64
3skin/color...al.png
windows10-2004-x64
3skin/color...mbs.db
windows10-2004-x64
3skin/color...er.png
windows10-2004-x64
3skin/color...al.png
windows10-2004-x64
3yccV3.dll
windows10-2004-x64
8Analysis
-
max time kernel
144s -
max time network
153s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
29-06-2024 07:13
Static task
static1
Behavioral task
behavioral1
Sample
net6.0-windows.zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral2
Sample
assets/fonts/ac3plug/ac3plug.zip
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
assets/fonts/kust.ttf
Resource
win10v2004-20240611-en
Behavioral task
behavioral4
Sample
assets/fonts/monof_tt-be11.txt
Resource
win10v2004-20240226-en
Behavioral task
behavioral5
Sample
assets/fonts/opensticks.ttf
Resource
win10v2004-20240508-en
Behavioral task
behavioral6
Sample
assets/fonts/spincycle_3d_ot.otf
Resource
win10v2004-20240611-en
Behavioral task
behavioral7
Sample
assets/fonts/summer85.ttf
Resource
win10v2004-20240611-en
Behavioral task
behavioral8
Sample
assets/fonts/twemojimozilla.txt
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
assets/models/editor/camera/camera.mdl
Resource
win10v2004-20240611-en
Behavioral task
behavioral10
Sample
assets/models/util/composelayer.json
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
assets/models/util/composelayer_depthtest.json
Resource
win10v2004-20240508-en
Behavioral task
behavioral12
Sample
assets/models/util/fullscreenlayer.json
Resource
win10v2004-20240611-en
Behavioral task
behavioral13
Sample
assets/models/util/projectlayer.json
Resource
win10v2004-20240611-en
Behavioral task
behavioral14
Sample
assets/models/util/solidlayer.json
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
assets/models/util/solidlayer_depthtest.json
Resource
win10v2004-20240508-en
Behavioral task
behavioral16
Sample
mfccpu.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral17
Sample
picker.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral18
Sample
ref/MagicOrbwalker1.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
releases.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral20
Sample
skin/Color3/sz0/App_Hover.png
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
skin/Color3/sz0/App_Normal.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral22
Sample
skin/Color3/sz1/App_Hover.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral23
Sample
skin/Color3/sz1/App_Normal.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral24
Sample
skin/color0/sz0/App_Hover.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral25
Sample
skin/color0/sz0/App_Normal.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral26
Sample
skin/color0/sz0/Thumbs.db
Resource
win10v2004-20240508-en
Behavioral task
behavioral27
Sample
skin/color0/sz1/App_Hover.png
Resource
win10v2004-20240508-en
Behavioral task
behavioral28
Sample
skin/color0/sz1/App_Normal.png
Resource
win10v2004-20240508-en
Behavioral task
behavioral29
Sample
skin/color0/sz1/Thumbs.db
Resource
win10v2004-20240508-en
Behavioral task
behavioral30
Sample
skin/color1/sz0/App_Hover.png
Resource
win10v2004-20240226-en
Behavioral task
behavioral31
Sample
skin/color1/sz0/App_Normal.png
Resource
win10v2004-20240611-en
Behavioral task
behavioral32
Sample
yccV3.dll
Resource
win10v2004-20240508-en
General
-
Target
yccV3.dll
-
Size
231KB
-
MD5
101d63244d7ee78e902e1bebfafa5acb
-
SHA1
0d501d964237e3bb4c29ed893da8bc084d8b5cd0
-
SHA256
b644b78f3c0c949e454f13685790b9f91fea87715258adbc81c175c2794a09fb
-
SHA512
17969217a6045f401152c73c2edab2fc4017a721894759f6d8de5cf42c9c32f3a86ef3f62423d76351595896a367212e7a683b3c704879d379443c359a89ad69
-
SSDEEP
3072:TYhDJzq4xanmtqJqZRpXoKnH3nMwmFh9hAktZsuKuxNuDvP2m3Ofbj9E8DWuZHPM:QldXWthAktLHYafNLnZHZ5DM
Malware Config
Signatures
-
Drops file in Drivers directory 2 IoCs
Processes:
rundll32.exedescription ioc process File opened for modification C:\Windows\System32\drivers\gdrv3.sys rundll32.exe File created C:\Windows\System32\drivers\gdrv3.sys rundll32.exe -
Suspicious behavior: LoadsDriver 1 IoCs
Processes:
pid process 656 -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
rundll32.exedescription pid process target process PID 1600 wrote to memory of 908 1600 rundll32.exe rundll32.exe PID 1600 wrote to memory of 908 1600 rundll32.exe rundll32.exe PID 1600 wrote to memory of 908 1600 rundll32.exe rundll32.exe