Analysis
-
max time kernel
16s -
max time network
17s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 09:55
Static task
static1
1 signatures
Behavioral task
behavioral1
Sample
FR OPTI.exe
Resource
win7-20240611-en
windows7-x64
2 signatures
150 seconds
Behavioral task
behavioral2
Sample
FR OPTI.exe
Resource
win10v2004-20240508-en
windows10-2004-x64
4 signatures
150 seconds
General
-
Target
FR OPTI.exe
-
Size
861KB
-
MD5
568cd98420699a0a18c181b7d2614c57
-
SHA1
d8069b859a1bc0c36b9d72af06e8b5d94fec1b5f
-
SHA256
62ee006d2f4afb965c7ce1a3bb1b2085b72da57c0a6c79ad0cae12fc41fb2a96
-
SHA512
24d8872e071c65967e13c1795170c0859e368a4e64ae5ab0debcd80083cc3623977a7b22024003e79b3e13ff4286bb0f734b5f81ce7e34ea2ed455ab40aa215b
-
SSDEEP
24576:W4TQcPTAcySiDNpfVkqgfPyU8/oa8reuaD:b70nS4pfVkqgy6r3a
Score
3/10
Malware Config
Signatures
-
Program crash 1 IoCs
Processes:
WerFault.exepid pid_target process target process 1956 2652 WerFault.exe FR OPTI.exe -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
FR OPTI.exedescription pid process target process PID 2652 wrote to memory of 1956 2652 FR OPTI.exe WerFault.exe PID 2652 wrote to memory of 1956 2652 FR OPTI.exe WerFault.exe PID 2652 wrote to memory of 1956 2652 FR OPTI.exe WerFault.exe PID 2652 wrote to memory of 1956 2652 FR OPTI.exe WerFault.exe