Overview
overview
10Static
static
3R B X 9 5.rar
windows7-x64
3R B X 9 5.rar
windows10-2004-x64
3R B X 9 5/Client.exe
windows7-x64
1R B X 9 5/Client.exe
windows10-2004-x64
1R B X 9 5/...or.exe
windows7-x64
7R B X 9 5/...or.exe
windows10-2004-x64
10R B X 9 5/ai.cfg
windows7-x64
3R B X 9 5/ai.cfg
windows10-2004-x64
3R B X 9 5/cacert.pem
windows7-x64
3R B X 9 5/cacert.pem
windows10-2004-x64
3R B X 9 5/config.vdf
windows7-x64
3R B X 9 5/config.vdf
windows10-2004-x64
3Analysis
-
max time kernel
49s -
max time network
17s -
platform
windows7_x64 -
resource
win7-20240419-en -
resource tags
arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 07:37
Static task
static1
Behavioral task
behavioral1
Sample
R B X 9 5.rar
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
R B X 9 5.rar
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
R B X 9 5/Client.exe
Resource
win7-20240221-en
Behavioral task
behavioral4
Sample
R B X 9 5/Client.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
R B X 9 5/Roblox Executor.exe
Resource
win7-20240419-en
Behavioral task
behavioral6
Sample
R B X 9 5/Roblox Executor.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral7
Sample
R B X 9 5/ai.cfg
Resource
win7-20240611-en
Behavioral task
behavioral8
Sample
R B X 9 5/ai.cfg
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
R B X 9 5/cacert.pem
Resource
win7-20240221-en
Behavioral task
behavioral10
Sample
R B X 9 5/cacert.pem
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
R B X 9 5/config.vdf
Resource
win7-20240508-en
Behavioral task
behavioral12
Sample
R B X 9 5/config.vdf
Resource
win10v2004-20240611-en
General
-
Target
R B X 9 5/Roblox Executor.exe
-
Size
359KB
-
MD5
e3106b33d419c2b1d7920d8f55e0b5c8
-
SHA1
3bfc3ec1727477c0df43644268d4c9ebdea00662
-
SHA256
cea6948d7fcd91a07f883c0216bbf0c8a71bbbd860b8752d965ff4421d2ec01f
-
SHA512
01113183c50a1eab161b5117b96a856ce457c3a30f9dcad949cd4e9020e72409be2a4e56fce7f523bd648daa1aed06e2a1f1c3ae0f3bfb6b0520e979986a9f50
-
SSDEEP
6144:afP6YNEL+sAO6gaZKKfL2GKfaVeV+mTlEIwrjef7UBgHvMW7xJpg1vLfIGfXP:af10AYaZZDi7VTlfwrjef7UBgHvMW7xi
Malware Config
Signatures
-
Loads dropped DLL 1 IoCs
Processes:
Roblox Executor.exepid process 1968 Roblox Executor.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
\Users\Admin\AppData\Roaming\d3d9.dllFilesize
424KB
MD5ec28aef5418f7157f9e826983146133c
SHA1ce3d2ea83b283f32f9d8a162f5a6393eab5572a2
SHA256adf0a47152697ea16658d2af4986ed1d0248c31421c548dbeb8d05d6c1beb6d9
SHA5123755fa7d8afd9e51946c4f41ac651175ada3623355a4602666f0a338323dd72906dfdcfe9c4b5f73aeef6db5ea4d5e6d281694daf9a3f863859ce38cb4e016d7
-
memory/1968-0-0x0000000074B8E000-0x0000000074B8F000-memory.dmpFilesize
4KB
-
memory/1968-1-0x0000000000EA0000-0x0000000000F04000-memory.dmpFilesize
400KB
-
memory/1968-2-0x0000000000480000-0x0000000000486000-memory.dmpFilesize
24KB
-
memory/1968-7-0x0000000076160000-0x0000000076221000-memory.dmpFilesize
772KB
-
memory/1968-8-0x0000000074B80000-0x000000007526E000-memory.dmpFilesize
6.9MB