Analysis

  • max time kernel
    51s
  • max time network
    54s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    29-06-2024 20:23

General

  • Target

    0d5c74ededad90cf94e042cda47c65f13741944ff9a8832dda9d21a4ed679299.exe

  • Size

    15.7MB

  • MD5

    cab07f6f3b884d73cdb3345bbce1955c

  • SHA1

    014dec3e22e50270fcf82e9cb0072308bf497e90

  • SHA256

    0d5c74ededad90cf94e042cda47c65f13741944ff9a8832dda9d21a4ed679299

  • SHA512

    b8490a0e079c9e6c9d8714135f35cacc7556c2a8255094a3d3aca154c94d79154bac990562c948633e85547239961e1af8bacf71320587d1fc32570e43aeeba7

  • SSDEEP

    196608:3TUqromur2qlWio0eLZ4z5YqZ8uMJfVfUCjP3+qJVEJKlDoSNOl/ApH8ku4SAstv:3TobGZ4zUuA9R3+qUKjNONIwZtv

Score
7/10

Malware Config

Signatures

  • VMProtect packed file 1 IoCs

    Detects executables packed with VMProtect commercial packer.

  • Suspicious use of NtSetInformationThreadHideFromDebugger 1 IoCs
  • Program crash 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\0d5c74ededad90cf94e042cda47c65f13741944ff9a8832dda9d21a4ed679299.exe
    "C:\Users\Admin\AppData\Local\Temp\0d5c74ededad90cf94e042cda47c65f13741944ff9a8832dda9d21a4ed679299.exe"
    1⤵
    • Suspicious use of NtSetInformationThreadHideFromDebugger
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of SetWindowsHookEx
    PID:2464
    • C:\Windows\SysWOW64\WerFault.exe
      C:\Windows\SysWOW64\WerFault.exe -u -p 2464 -s 628
      2⤵
      • Program crash
      PID:2536
  • C:\Windows\SysWOW64\WerFault.exe
    C:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 2464 -ip 2464
    1⤵
      PID:4912

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2464-0-0x0000000001560000-0x0000000001561000-memory.dmp
      Filesize

      4KB

    • memory/2464-2-0x0000000000FEB000-0x0000000001220000-memory.dmp
      Filesize

      2.2MB

    • memory/2464-1-0x0000000000400000-0x00000000013FF000-memory.dmp
      Filesize

      16.0MB

    • memory/2464-3-0x0000000000FEB000-0x0000000001220000-memory.dmp
      Filesize

      2.2MB