Analysis

  • max time kernel
    120s
  • max time network
    125s
  • platform
    windows7_x64
  • resource
    win7-20231129-en
  • resource tags

    arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system
  • submitted
    30-06-2024 14:40

General

  • Target

    lib/xmlrpc/server.pyc

  • Size

    28KB

  • MD5

    9fd2a953393d41d0c4e07e06024eef95

  • SHA1

    f42fd7db71a5e180566f5a7a5eee996165b8ad65

  • SHA256

    56861327dc5505e476aec6b9140c92e244f18ffe4af46edd39fd8cba1f7c2dd0

  • SHA512

    9bb56ca570fb8733de59ccf8f0a6b6769e9b0596d95604954287bb7afbd1d1951d33dd1eb4061e927603e8e823d7d48e5572fe1c8541d1de7300274fc9c168f2

  • SSDEEP

    768:x+gCW4nOS5GfOrspGy+tRLFppz4hcIBOGowb0:x+gCNYfOi/OMOg0

Score
3/10

Malware Config

Signatures

  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies registry class 9 IoCs
  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs
  • Suspicious use of WriteProcessMemory 7 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    cmd /c C:\Users\Admin\AppData\Local\Temp\lib\xmlrpc\server.pyc
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:952
    • C:\Windows\system32\rundll32.exe
      "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\Admin\AppData\Local\Temp\lib\xmlrpc\server.pyc
      2⤵
      • Modifies registry class
      • Suspicious use of WriteProcessMemory
      PID:2100
      • C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
        "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\lib\xmlrpc\server.pyc"
        3⤵
        • Suspicious behavior: GetForegroundWindowSpam
        • Suspicious use of SetWindowsHookEx
        PID:2720

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
    Filesize

    3KB

    MD5

    795bff9e0e4279c9d2eb6a0783bc0b63

    SHA1

    60afc16f35c2fc542af1c53af453d62f8fec19b5

    SHA256

    f8fff12559ec6da6173cb29e5f145ca18fad56e491df29380a0c3f947aef2ee0

    SHA512

    90244030d563095fd2e64264fdcb52d56b49f9fe5e2f570e1a7d5e3c5a8274df7f07d24d090e21fd817c76e3bece67af51555014edb6cecd20c3a2ceee16bd01