Analysis

  • max time kernel
    140s
  • max time network
    95s
  • platform
    windows11-21h2_x64
  • resource
    win11-20240611-en
  • resource tags

    arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    30-06-2024 14:25

General

  • Target

    ae9ecc25a582c737f43bf7531e065dad393ae59cc779061c306697fa891bac01.exe

  • Size

    549KB

  • MD5

    652838c3937011d64bfb0b320e486e9f

  • SHA1

    822f25f8e9c1945a9286c3099e6948aa7191a1b6

  • SHA256

    ae9ecc25a582c737f43bf7531e065dad393ae59cc779061c306697fa891bac01

  • SHA512

    d996fb1f6dfff04a29aaab2a39a8bfb78c559cda98989cd1b3600b9e16ebbf9ef8a0dced28897f3535b7f2d0d619323653725b6b000ee27adef8e27a75b687d9

  • SSDEEP

    12288:mVO89AEKEwJYBu56ns/GNGRlD5n3QJY/RgI17jg+0AHd:eOlEKXJG6atYD5d57jb0AHd

Score
6/10

Malware Config

Signatures

  • Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs

    Bootkits write to the MBR to gain persistence at a level below the operating system.

Processes

  • C:\Users\Admin\AppData\Local\Temp\ae9ecc25a582c737f43bf7531e065dad393ae59cc779061c306697fa891bac01.exe
    "C:\Users\Admin\AppData\Local\Temp\ae9ecc25a582c737f43bf7531e065dad393ae59cc779061c306697fa891bac01.exe"
    1⤵
    • Writes to the Master Boot Record (MBR)
    PID:3200

Network

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/3200-1-0x0000000002DE0000-0x0000000002EE0000-memory.dmp
    Filesize

    1024KB

  • memory/3200-2-0x0000000004990000-0x00000000049FB000-memory.dmp
    Filesize

    428KB

  • memory/3200-3-0x0000000000400000-0x000000000046F000-memory.dmp
    Filesize

    444KB

  • memory/3200-4-0x0000000000400000-0x0000000002C42000-memory.dmp
    Filesize

    40.3MB

  • memory/3200-5-0x0000000000400000-0x0000000002C42000-memory.dmp
    Filesize

    40.3MB

  • memory/3200-7-0x0000000002DE0000-0x0000000002EE0000-memory.dmp
    Filesize

    1024KB

  • memory/3200-8-0x0000000004990000-0x00000000049FB000-memory.dmp
    Filesize

    428KB

  • memory/3200-9-0x0000000000400000-0x000000000046F000-memory.dmp
    Filesize

    444KB