Overview
overview
10Static
static
7Loaderldsaldls.exe
windows10-1703-x64
10⌚/output.exe
windows10-1703-x64
⌚/output2.exe
windows10-1703-x64
Source/QtG...re.dll
windows10-1703-x64
1Source/QtG...lur.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
3Source/QtQ...yle.js
windows10-1703-x64
4Source/QtQ...in.dll
windows10-1703-x64
1Source/QtQ...iew.js
windows10-1703-x64
3Source/QtQ...iew.js
windows10-1703-x64
3Source/QtQ...umn.js
windows10-1703-x64
3Source/QtQ...rea.js
windows10-1703-x64
3Source/QtQ...iew.js
windows10-1703-x64
3Source/QtQ...in.dll
windows10-1703-x64
1Source/QtQ...in.dll
windows10-1703-x64
1Source/QtQ...in.dll
windows10-1703-x64
1Source/QtQ...in.dll
windows10-1703-x64
1Source/QtW...in.dll
windows10-1703-x64
1Source/QtW...as.dll
windows10-1703-x64
1Source/aud...pi.dll
windows10-1703-x64
1Source/aud...ws.dll
windows10-1703-x64
1Source/ima...if.dll
windows10-1703-x64
1Source/ima...co.dll
windows10-1703-x64
1Source/ima...eg.dll
windows10-1703-x64
1Source/ima...vg.dll
windows10-1703-x64
1Source/ima...bp.dll
windows10-1703-x64
1Source/pla...ws.dll
windows10-1703-x64
1Source/sty...le.dll
windows10-1703-x64
1Analysis
-
max time kernel
299s -
max time network
327s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
30-06-2024 23:36
Behavioral task
behavioral1
Sample
Loaderldsaldls.exe
Resource
win10-20240404-en
Behavioral task
behavioral2
Sample
⌚/output.exe
Resource
win10-20240611-en
Behavioral task
behavioral3
Sample
⌚/output2.exe
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
Source/QtGraphicalEffects/Qt5WebEngineCore.dll
Resource
win10-20240404-en
Behavioral task
behavioral5
Sample
Source/QtGraphicalEffects/RadialBlur.js
Resource
win10-20240404-en
Behavioral task
behavioral6
Sample
Source/QtQuick/Controls/Styles/Base/StatusIndicatorStyle.js
Resource
win10-20240404-en
Behavioral task
behavioral7
Sample
Source/QtQuick/Controls/Styles/Desktop/ComboBoxStyle.js
Resource
win10-20240404-en
Behavioral task
behavioral8
Sample
Source/QtQuick/Controls/Styles/Desktop/GroupBoxStyle.js
Resource
win10-20240404-en
Behavioral task
behavioral9
Sample
Source/QtQuick/Controls/Styles/Desktop/MenuStyle.js
Resource
win10-20240611-en
Behavioral task
behavioral10
Sample
Source/QtQuick/Controls/Styles/Desktop/SpinBoxStyle.js
Resource
win10-20240404-en
Behavioral task
behavioral11
Sample
Source/QtQuick/Controls/Styles/Desktop/TreeViewStyle.js
Resource
win10-20240404-en
Behavioral task
behavioral12
Sample
Source/QtQuick/Controls/Styles/Flat/qtquickextrasflatplugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral13
Sample
Source/QtQuick/Controls/TabView.js
Resource
win10-20240404-en
Behavioral task
behavioral14
Sample
Source/QtQuick/Controls/TableView.js
Resource
win10-20240404-en
Behavioral task
behavioral15
Sample
Source/QtQuick/Controls/TableViewColumn.js
Resource
win10-20240404-en
Behavioral task
behavioral16
Sample
Source/QtQuick/Controls/TextArea.js
Resource
win10-20240611-en
Behavioral task
behavioral17
Sample
Source/QtQuick/Controls/TreeView.js
Resource
win10-20240404-en
Behavioral task
behavioral18
Sample
Source/QtQuick/Controls/qtquickcontrolsplugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral19
Sample
Source/QtQuick/Layouts/qquicklayoutsplugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral20
Sample
Source/QtQuick/Templates.2/qtquicktemplates2plugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral21
Sample
Source/QtQuick/Window.2/windowplugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral22
Sample
Source/QtWebEngine/qtwebengineplugin.dll
Resource
win10-20240404-en
Behavioral task
behavioral23
Sample
Source/QtWinExtras/qml_winextras.dll
Resource
win10-20240611-en
Behavioral task
behavioral24
Sample
Source/audio/qtaudio_wasapi.dll
Resource
win10-20240404-en
Behavioral task
behavioral25
Sample
Source/audio/qtaudio_windows.dll
Resource
win10-20240404-en
Behavioral task
behavioral26
Sample
Source/imageformats/qgif.dll
Resource
win10-20240404-en
Behavioral task
behavioral27
Sample
Source/imageformats/qico.dll
Resource
win10-20240404-en
Behavioral task
behavioral28
Sample
Source/imageformats/qjpeg.dll
Resource
win10-20240404-en
Behavioral task
behavioral29
Sample
Source/imageformats/qsvg.dll
Resource
win10-20240611-en
Behavioral task
behavioral30
Sample
Source/imageformats/qwebp.dll
Resource
win10-20240404-en
Behavioral task
behavioral31
Sample
Source/platforms/qwindows.dll
Resource
win10-20240404-en
Behavioral task
behavioral32
Sample
Source/styles/qwindowsvistastyle.dll
Resource
win10-20240611-en
General
-
Target
Source/QtQuick/Controls/Styles/Desktop/TreeViewStyle.js
-
Size
2KB
-
MD5
e0aa379b2a0c01ba02d9dd128c74bfbb
-
SHA1
4e2005633527069eede98c33628428c358ce0c64
-
SHA256
1c645cda72e81f295d03fed5142c502651c9d5f0418788f5f3c53a5720c2351e
-
SHA512
28bf0f38bd956458655590f2abddc0a14ab80cd395f18b710c0c9e973ee1c033615302c94d0bb4906d711e82880db0239c3c81ea36845d8d882e1d38a1ee3502
Malware Config
Signatures
-
Drops file in Windows directory 2 IoCs
Processes:
taskmgr.exedescription ioc process File created C:\Windows\rescache\_merged\4183903823\2290032291.pri taskmgr.exe File created C:\Windows\rescache\_merged\1601268389\715946058.pri taskmgr.exe -
Command and Scripting Interpreter: JavaScript 1 TTPs
-
Checks SCSI registry key(s) 3 TTPs 3 IoCs
SCSI information is often read in order to detect sandboxing environments.
Processes:
taskmgr.exedescription ioc process Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_QEMU&Prod_HARDDISK\4&215468a5&0&000000\Properties\{b725f130-47ef-101a-a5f1-02608c9eebac}\000A taskmgr.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_QEMU&Prod_HARDDISK\4&215468a5&0&000000\FriendlyName taskmgr.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_QEMU&Prod_HARDDISK\4&215468a5&0&000000 taskmgr.exe -
Checks processor information in registry 2 TTPs 2 IoCs
Processor information is often read in order to detect sandboxing environments.
Processes:
taskmgr.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 taskmgr.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString taskmgr.exe -
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
taskmgr.exepid process 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe -
Suspicious use of AdjustPrivilegeToken 3 IoCs
Processes:
taskmgr.exedescription pid process Token: SeDebugPrivilege 504 taskmgr.exe Token: SeSystemProfilePrivilege 504 taskmgr.exe Token: SeCreateGlobalPrivilege 504 taskmgr.exe -
Suspicious use of FindShellTrayWindow 64 IoCs
Processes:
taskmgr.exepid process 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe -
Suspicious use of SendNotifyMessage 64 IoCs
Processes:
taskmgr.exepid process 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe 504 taskmgr.exe
Processes
-
C:\Windows\system32\wscript.exewscript.exe C:\Users\Admin\AppData\Local\Temp\Source\QtQuick\Controls\Styles\Desktop\TreeViewStyle.js1⤵
-
C:\Windows\system32\taskmgr.exe"C:\Windows\system32\taskmgr.exe" /01⤵
- Drops file in Windows directory
- Checks SCSI registry key(s)
- Checks processor information in registry
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage