Analysis

  • max time kernel
    140s
  • max time network
    51s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    30-06-2024 09:38

General

  • Target

    Wave Goodbye.exe

  • Size

    6.0MB

  • MD5

    b67c09157b260b02037a716d28d7c34f

  • SHA1

    a6da5549351e78fda395b5381dcf9e14240390fd

  • SHA256

    ceb6a0b8e1c27c75155ab28b9283fe488ae5daca15b0cc58ebfc009200c8e824

  • SHA512

    61cc65311af74f83ea950ef54661a5421df67026f7760e257ae3701b3b339f554ac1b42a63f2adafe142ad71a81c545b6749aac0a4f5c78eccd90d072fb7bbad

  • SSDEEP

    98304:dHx3rQ9UT/cnDEuzHEAtpW1pAT0WaDMyaATQKC2witrFr9vQVN9x3gHWdFISYft4:73rpbcnDEuzkAtpWzATIaAEHVYJJmN/P

Malware Config

Signatures

  • Identifies VirtualBox via ACPI registry values (likely anti-VM) 2 TTPs 1 IoCs
  • Drops file in Drivers directory 1 IoCs
  • Checks BIOS information in registry 2 TTPs 2 IoCs

    BIOS information is often read in order to detect sandboxing environments.

  • Themida packer 21 IoCs

    Detects Themida, an advanced Windows software protection system.

  • Checks whether UAC is enabled 1 TTPs 1 IoCs
  • Suspicious use of NtSetInformationThreadHideFromDebugger 1 IoCs
  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Enumerates system info in registry 2 TTPs 3 IoCs
  • Modifies system certificate store 2 TTPs 2 IoCs
  • Suspicious behavior: EnumeratesProcesses 4 IoCs
  • Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary 2 IoCs
  • Suspicious use of FindShellTrayWindow 26 IoCs
  • Suspicious use of SendNotifyMessage 24 IoCs
  • Suspicious use of WriteProcessMemory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\Wave Goodbye.exe
    "C:\Users\Admin\AppData\Local\Temp\Wave Goodbye.exe"
    1⤵
    • Identifies VirtualBox via ACPI registry values (likely anti-VM)
    • Drops file in Drivers directory
    • Checks BIOS information in registry
    • Checks whether UAC is enabled
    • Suspicious use of NtSetInformationThreadHideFromDebugger
    • Modifies system certificate store
    • Suspicious use of WriteProcessMemory
    PID:4884
    • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
      "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://discord.gg/6NNYUEXAR2
      2⤵
      • Enumerates system info in registry
      • Suspicious behavior: EnumeratesProcesses
      • Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
      • Suspicious use of FindShellTrayWindow
      • Suspicious use of SendNotifyMessage
      • Suspicious use of WriteProcessMemory
      PID:100
      • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
        "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=92.0.4515.131 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=92.0.902.67 --initial-client-data=0xfc,0x100,0x104,0xd8,0x108,0x7ffa3b1046f8,0x7ffa3b104708,0x7ffa3b104718
        3⤵
          PID:116
        • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
          "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=2152,8178855197204245962,568361212419817147,131072 --gpu-preferences=UAAAAAAAAADgAAAQAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHgAAAAAAAAAeAAAAAAAAAAoAAAABAAAACAAAAAAAAAAKAAAAAAAAAAwAAAAAAAAADgAAAAAAAAAEAAAAAAAAAAAAAAADQAAABAAAAAAAAAAAQAAAA0AAAAQAAAAAAAAAAQAAAANAAAAEAAAAAAAAAAHAAAADQAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=2164 /prefetch:2
          3⤵
            PID:948
          • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
            "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=2152,8178855197204245962,568361212419817147,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 /prefetch:3
            3⤵
            • Suspicious behavior: EnumeratesProcesses
            PID:3532
          • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
            "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=2152,8178855197204245962,568361212419817147,131072 --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2760 /prefetch:8
            3⤵
              PID:2064
            • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2152,8178855197204245962,568361212419817147,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3276 /prefetch:1
              3⤵
                PID:3144
              • C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=2152,8178855197204245962,568361212419817147,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3284 /prefetch:1
                3⤵
                  PID:3440
            • C:\Windows\System32\CompPkgSrv.exe
              C:\Windows\System32\CompPkgSrv.exe -Embedding
              1⤵
                PID:2304
              • C:\Windows\System32\CompPkgSrv.exe
                C:\Windows\System32\CompPkgSrv.exe -Embedding
                1⤵
                  PID:2892

                Network

                MITRE ATT&CK Matrix ATT&CK v13

                Defense Evasion

                Virtualization/Sandbox Evasion

                1
                T1497

                Subvert Trust Controls

                1
                T1553

                Install Root Certificate

                1
                T1553.004

                Modify Registry

                1
                T1112

                Discovery

                Query Registry

                3
                T1012

                Virtualization/Sandbox Evasion

                1
                T1497

                System Information Discovery

                4
                T1082

                Replay Monitor

                Loading Replay Monitor...

                Downloads

                • C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
                  Filesize

                  152B

                  MD5

                  4158365912175436289496136e7912c2

                  SHA1

                  813d11f772b1cfe9ceac2bf37f4f741e5e8fbe59

                  SHA256

                  354de4b033ba6e4d85f94d91230cb8501f62e0a4e302cd4076c7e0ad73bedbd1

                  SHA512

                  74b4f7b24ad4ea395f3a4cd8dbfae54f112a7c87bce3d286ee5161f6b63d62dfa19bb0d96bb7ed1c6d925f5697a2580c25023d5052c6a09992e6fd9dd49ea82b

                • C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
                  Filesize

                  152B

                  MD5

                  ce4c898f8fc7601e2fbc252fdadb5115

                  SHA1

                  01bf06badc5da353e539c7c07527d30dccc55a91

                  SHA256

                  bce2dfaa91f0d44e977e0f79c60e64954a7b9dc828b0e30fbaa67dbe82f750aa

                  SHA512

                  80fff4c722c8d3e69ec4f09510779b7e3518ae60725d2d36903e606a27ec1eaedbdbfac5b662bf2c19194c572ccf0125445f22a907b329ad256e6c00b9cf032c

                • C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Preferences
                  Filesize

                  5KB

                  MD5

                  a770ed3086b92024f7715d1155730677

                  SHA1

                  909fea314a98994d250b08cd8c864229ea05adc9

                  SHA256

                  389eccd47ed29ba7510af3a1571688cd6c4a377c77f3a837b1f78a6089565144

                  SHA512

                  8d5f07cc291feda5695412b6bdcee0156fc64bbeac6fee947e29b8d842d85c1edc8ceff51df8b78c5eedecd0b94fdf73fcdf90a9f675e9da1b5080dc557513f6

                • C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Local State
                  Filesize

                  8KB

                  MD5

                  cf66fa915445a15434fcc579c7b89c59

                  SHA1

                  ce1da35b26aef603e009e5e28f03f4f1671bb72b

                  SHA256

                  22bc47222ad2c64cef9c82cad4f5a963ed419eb3422e121f3ba8fdff294fd3d3

                  SHA512

                  27a70514dd6a90e9c656294233e0fc4f453b7ebac5a608a816dd80f2f6c040704f2ab2d8c88435f2c529f827a6c6095699b73c8fd15936139bb23db318a3f11c

                • C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\ShaderCache\GPUCache\data_1
                  Filesize

                  264KB

                  MD5

                  f50f89a0a91564d0b8a211f8921aa7de

                  SHA1

                  112403a17dd69d5b9018b8cede023cb3b54eab7d

                  SHA256

                  b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec

                  SHA512

                  bf8cda48cf1ec4e73f0dd1d4fa5562af1836120214edb74957430cd3e4a2783e801fa3f4ed2afb375257caeed4abe958265237d6e0aacf35a9ede7a2e8898d58

                • C:\Windows\system32\drivers\etc\hosts
                  Filesize

                  1KB

                  MD5

                  deca688b3a2d7e1224e65a13c66b405d

                  SHA1

                  5d088d911e53b05860d2294f081b7a56614c1b1b

                  SHA256

                  efe68251dcfee5e61bce15c9028f4e237c45e24f23f66d0c9acf5355ba709341

                  SHA512

                  8ed11f7e130d1d0d5f554849e9ad181f60d242d21aa6019307df20833e7646705716f591b13c9db0ba8643e8800816dd6b691572c80973f540fba14cc84d47be

                • \??\pipe\LOCAL\crashpad_100_OCAPMZQZIUTDUXQK
                  MD5

                  d41d8cd98f00b204e9800998ecf8427e

                  SHA1

                  da39a3ee5e6b4b0d3255bfef95601890afd80709

                  SHA256

                  e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

                  SHA512

                  cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e

                • memory/4884-102-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-3-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-103-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-2-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-1-0x00007FFA492B0000-0x00007FFA492B2000-memory.dmp
                  Filesize

                  8KB

                • memory/4884-4-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-47-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-0-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-104-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-101-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-113-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-6-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-100-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-105-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-106-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-107-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-108-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-109-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-110-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-111-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-112-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB

                • memory/4884-5-0x0000000140000000-0x0000000140F65000-memory.dmp
                  Filesize

                  15.4MB