Analysis
-
max time kernel
117s -
max time network
125s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 07:21
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
SolaraBootstrapper.exe
Resource
win7-20240221-en
2 signatures
150 seconds
General
-
Target
SolaraBootstrapper.exe
-
Size
13KB
-
MD5
0cc81729f4bd4a6eac95cc442bc8df2a
-
SHA1
5d5f367e720684dd64cfb5340d9911ec0782fdac
-
SHA256
92960ae4a38d896418a14a1db5ba1547aa273443790e858d00dac4ce64550c2a
-
SHA512
f6fc1fca47e4620e24652d8dc2aa88cdd7363172b31122c05d262349aeec88407a2b3fbbc4e4834c359960d4981fb9f674cfbfd9d5743dc917df72a3ebfb3c90
-
SSDEEP
192:+ZnqvqiVx1BLO77IaqaLHmr/XKTxnTjw1hOPVXmNjA:0nCVxoIaqayzKtnw1h6VKj
Score
6/10
Malware Config
Signatures
-
Legitimate hosting services abused for malware hosting/C2 1 TTPs 2 IoCs
-
Suspicious use of AdjustPrivilegeToken 1 IoCs
Processes:
SolaraBootstrapper.exedescription pid process Token: SeDebugPrivilege 3028 SolaraBootstrapper.exe
Processes
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/3028-0-0x0000000073F5E000-0x0000000073F5F000-memory.dmpFilesize
4KB
-
memory/3028-1-0x0000000000150000-0x000000000015A000-memory.dmpFilesize
40KB
-
memory/3028-2-0x0000000073F50000-0x000000007463E000-memory.dmpFilesize
6.9MB
-
memory/3028-3-0x0000000073F50000-0x000000007463E000-memory.dmpFilesize
6.9MB