Overview
overview
8Static
static
1Burpy-main.zip
windows7-x64
1Burpy-main.zip
windows10-2004-x64
1Burpy-main...en.jar
windows7-x64
1Burpy-main...en.jar
windows10-2004-x64
7Burpy-main...tup.sh
ubuntu-18.04-amd64
3Burpy-main...tup.sh
debian-9-armhf
4Burpy-main...tup.sh
debian-9-mips
7Burpy-main...tup.sh
debian-9-mipsel
7Burpy-main...up.ps1
windows7-x64
3Burpy-main...up.ps1
windows10-2004-x64
8Burpy-main...pro.sh
ubuntu-18.04-amd64
1Burpy-main...pro.sh
debian-9-armhf
1Burpy-main...pro.sh
debian-9-mips
1Burpy-main...pro.sh
debian-9-mipsel
1Burpy-main/keygen.jar
windows7-x64
1Burpy-main/keygen.jar
windows10-2004-x64
7Burpy-main/loader.jar
windows7-x64
1Burpy-main/loader.jar
windows10-2004-x64
7Analysis
-
max time kernel
147s -
max time network
151s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
29-06-2024 17:13
Static task
static1
Behavioral task
behavioral1
Sample
Burpy-main.zip
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
Burpy-main.zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
Burpy-main/BurpLoaderKeygen.jar
Resource
win7-20240611-en
Behavioral task
behavioral4
Sample
Burpy-main/BurpLoaderKeygen.jar
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
Burpy-main/Linux_setup.sh
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral6
Sample
Burpy-main/Linux_setup.sh
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral7
Sample
Burpy-main/Linux_setup.sh
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral8
Sample
Burpy-main/Linux_setup.sh
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral9
Sample
Burpy-main/Windows_setup.ps1
Resource
win7-20240221-en
Behavioral task
behavioral10
Sample
Burpy-main/Windows_setup.ps1
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
Burpy-main/burpsuite_pro.sh
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral12
Sample
Burpy-main/burpsuite_pro.sh
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral13
Sample
Burpy-main/burpsuite_pro.sh
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral14
Sample
Burpy-main/burpsuite_pro.sh
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral15
Sample
Burpy-main/keygen.jar
Resource
win7-20240611-en
Behavioral task
behavioral16
Sample
Burpy-main/keygen.jar
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
Burpy-main/loader.jar
Resource
win7-20240508-en
Behavioral task
behavioral18
Sample
Burpy-main/loader.jar
Resource
win10v2004-20240508-en
General
-
Target
Burpy-main/loader.jar
-
Size
29KB
-
MD5
56a0eef3a96bf373db1298bc6cb63158
-
SHA1
f9fb9175a901f4fede20b9d61eb4fadafdd1feea
-
SHA256
1e288c686963eafc34411d4f94265eb1809492ab57a474848669eb3285a2afb3
-
SHA512
d6165e567c80cd04c2506f285d48fb3e2dd6d46e4eda3b9bf76c2ea585ac446807ccabc02c4f8a6bede36a8ac1d1737eab3840cfdc703123daeccd526593f492
-
SSDEEP
768:ccLie6lYEKyYSfk8tyPAR8NVgJMvtWHw1QgHpA:NLie6lYEKyYSfkwNY+MvtuWQgG
Malware Config
Signatures
-
Modifies file permissions 1 TTPs 1 IoCs
-
Suspicious use of SetWindowsHookEx 2 IoCs
Processes:
java.exepid process 4132 java.exe 4132 java.exe -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
java.exedescription pid process target process PID 4132 wrote to memory of 4520 4132 java.exe icacls.exe PID 4132 wrote to memory of 4520 4132 java.exe icacls.exe PID 4132 wrote to memory of 2332 4132 java.exe java.exe PID 4132 wrote to memory of 2332 4132 java.exe java.exe
Processes
-
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exejava -jar C:\Users\Admin\AppData\Local\Temp\Burpy-main\loader.jar1⤵
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\icacls.exeC:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M2⤵
- Modifies file permissions
-
C:\Program Files\Java\jre-1.8\bin\java.exe"C:\Program Files\Java\jre-1.8\bin\java.exe" -version2⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestampFilesize
46B
MD55ba0476865bd18d9e31dfcc464639b98
SHA1639c4d2c23d69213005c7a6434db551f19f62c14
SHA2569df8fc973c3858334e566994eefa288bb9728c2636dce0fa4e14aa35d052596b
SHA51296fd637479bd391d555497d7317fb4fad177e5374acf2da32398f231db50d52b09ccfb5297793edc8a28628e256577e25afcf52f464677cc214020c26982e016
-
memory/2332-41-0x000001AA09B60000-0x000001AA09DD0000-memory.dmpFilesize
2.4MB
-
memory/2332-53-0x000001AA09B60000-0x000001AA09DD0000-memory.dmpFilesize
2.4MB
-
memory/2332-51-0x000001AA082F0000-0x000001AA082F1000-memory.dmpFilesize
4KB
-
memory/4132-63-0x000002363ABE0000-0x000002363ABF0000-memory.dmpFilesize
64KB
-
memory/4132-19-0x000002363ABE0000-0x000002363ABF0000-memory.dmpFilesize
64KB
-
memory/4132-71-0x000002363ACB0000-0x000002363ACC0000-memory.dmpFilesize
64KB
-
memory/4132-26-0x000002363AC20000-0x000002363AC30000-memory.dmpFilesize
64KB
-
memory/4132-31-0x000002363AC40000-0x000002363AC50000-memory.dmpFilesize
64KB
-
memory/4132-30-0x000002363AC30000-0x000002363AC40000-memory.dmpFilesize
64KB
-
memory/4132-34-0x000002363AC50000-0x000002363AC60000-memory.dmpFilesize
64KB
-
memory/4132-70-0x000002363AC10000-0x000002363AC20000-memory.dmpFilesize
64KB
-
memory/4132-43-0x00000236390F0000-0x00000236390F1000-memory.dmpFilesize
4KB
-
memory/4132-20-0x000002363ABF0000-0x000002363AC00000-memory.dmpFilesize
64KB
-
memory/4132-52-0x000002363AC60000-0x000002363AC70000-memory.dmpFilesize
64KB
-
memory/4132-17-0x000002363ABD0000-0x000002363ABE0000-memory.dmpFilesize
64KB
-
memory/4132-68-0x000002363ACA0000-0x000002363ACB0000-memory.dmpFilesize
64KB
-
memory/4132-57-0x000002363A960000-0x000002363ABD0000-memory.dmpFilesize
2.4MB
-
memory/4132-61-0x000002363AC80000-0x000002363AC90000-memory.dmpFilesize
64KB
-
memory/4132-60-0x000002363ABD0000-0x000002363ABE0000-memory.dmpFilesize
64KB
-
memory/4132-65-0x000002363AC90000-0x000002363ACA0000-memory.dmpFilesize
64KB
-
memory/4132-64-0x000002363ABF0000-0x000002363AC00000-memory.dmpFilesize
64KB
-
memory/4132-2-0x000002363A960000-0x000002363ABD0000-memory.dmpFilesize
2.4MB
-
memory/4132-67-0x000002363AC00000-0x000002363AC10000-memory.dmpFilesize
64KB
-
memory/4132-58-0x000002363AC70000-0x000002363AC80000-memory.dmpFilesize
64KB
-
memory/4132-22-0x000002363AC00000-0x000002363AC10000-memory.dmpFilesize
64KB
-
memory/4132-25-0x000002363AC10000-0x000002363AC20000-memory.dmpFilesize
64KB
-
memory/4132-75-0x000002363ACC0000-0x000002363ACD0000-memory.dmpFilesize
64KB
-
memory/4132-74-0x000002363AC20000-0x000002363AC30000-memory.dmpFilesize
64KB
-
memory/4132-78-0x000002363AC30000-0x000002363AC40000-memory.dmpFilesize
64KB
-
memory/4132-83-0x000002363AC50000-0x000002363AC60000-memory.dmpFilesize
64KB
-
memory/4132-82-0x000002363ACE0000-0x000002363ACF0000-memory.dmpFilesize
64KB
-
memory/4132-81-0x000002363ACD0000-0x000002363ACE0000-memory.dmpFilesize
64KB
-
memory/4132-80-0x000002363AC40000-0x000002363AC50000-memory.dmpFilesize
64KB
-
memory/4132-84-0x00000236390F0000-0x00000236390F1000-memory.dmpFilesize
4KB
-
memory/4132-86-0x000002363ACF0000-0x000002363AD00000-memory.dmpFilesize
64KB
-
memory/4132-88-0x000002363AC60000-0x000002363AC70000-memory.dmpFilesize
64KB
-
memory/4132-90-0x000002363AC70000-0x000002363AC80000-memory.dmpFilesize
64KB
-
memory/4132-91-0x000002363AC80000-0x000002363AC90000-memory.dmpFilesize
64KB
-
memory/4132-92-0x000002363AC90000-0x000002363ACA0000-memory.dmpFilesize
64KB
-
memory/4132-94-0x000002363ACA0000-0x000002363ACB0000-memory.dmpFilesize
64KB
-
memory/4132-96-0x000002363ACB0000-0x000002363ACC0000-memory.dmpFilesize
64KB
-
memory/4132-97-0x000002363ACC0000-0x000002363ACD0000-memory.dmpFilesize
64KB
-
memory/4132-98-0x000002363ACD0000-0x000002363ACE0000-memory.dmpFilesize
64KB
-
memory/4132-99-0x000002363ACE0000-0x000002363ACF0000-memory.dmpFilesize
64KB
-
memory/4132-100-0x000002363ACF0000-0x000002363AD00000-memory.dmpFilesize
64KB