Analysis

  • max time kernel
    142s
  • max time network
    93s
  • platform
    windows11-21h2_x64
  • resource
    win11-20240611-en
  • resource tags

    arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    30-06-2024 14:48

General

  • Target

    44c24d69b2bcf7a889eb87eb7fa15dc1fe2c7c199b9636c455483b27170488ff.exe

  • Size

    549KB

  • MD5

    f70acba2db5874c1fbfe7aaa2e18e50a

  • SHA1

    6f1f4346c8513fdd192a176a4f891ce55b17aa12

  • SHA256

    44c24d69b2bcf7a889eb87eb7fa15dc1fe2c7c199b9636c455483b27170488ff

  • SHA512

    7a295047ba3d94b3504da7aca7f6c752425eff2c400b76b3b9004603fa3d740e35a39422bc393d7745423467fa054ec6e48e8b8a5ac32958d1c673024acd5b25

  • SSDEEP

    6144:XOVO89A16CjdswfCcmkaRHUaLsE44kkHwXJCS2onrt4vv8qC98J85chPR0cDfS:+VO89AYQdspcmk+1sE2kOt4vueJ8SXG

Score
6/10

Malware Config

Signatures

  • Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs

    Bootkits write to the MBR to gain persistence at a level below the operating system.

Processes

  • C:\Users\Admin\AppData\Local\Temp\44c24d69b2bcf7a889eb87eb7fa15dc1fe2c7c199b9636c455483b27170488ff.exe
    "C:\Users\Admin\AppData\Local\Temp\44c24d69b2bcf7a889eb87eb7fa15dc1fe2c7c199b9636c455483b27170488ff.exe"
    1⤵
    • Writes to the Master Boot Record (MBR)
    PID:2288

Network

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/2288-1-0x0000000002F10000-0x0000000003010000-memory.dmp
    Filesize

    1024KB

  • memory/2288-2-0x00000000049B0000-0x0000000004A1B000-memory.dmp
    Filesize

    428KB

  • memory/2288-3-0x0000000000400000-0x000000000046F000-memory.dmp
    Filesize

    444KB

  • memory/2288-4-0x0000000000400000-0x0000000002C42000-memory.dmp
    Filesize

    40.3MB

  • memory/2288-5-0x0000000000400000-0x0000000002C42000-memory.dmp
    Filesize

    40.3MB

  • memory/2288-7-0x0000000002F10000-0x0000000003010000-memory.dmp
    Filesize

    1024KB

  • memory/2288-8-0x00000000049B0000-0x0000000004A1B000-memory.dmp
    Filesize

    428KB

  • memory/2288-9-0x0000000000400000-0x000000000046F000-memory.dmp
    Filesize

    444KB