Analysis
-
max time kernel
122s -
max time network
123s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 15:18
Behavioral task
behavioral1
Sample
dc0a14b6_OpenFileToGetAccount30004302041006b.pdf
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
dc0a14b6_OpenFileToGetAccount30004302041006b.pdf
Resource
win10v2004-20240508-en
General
-
Target
dc0a14b6_OpenFileToGetAccount30004302041006b.pdf
-
Size
129KB
-
MD5
32a79ed56dbf7ecc65abf1062b762ee1
-
SHA1
2c36cbc7a6823d3a8b69db6160c512423f2ea1bc
-
SHA256
cc92078bde5bf55bf773a55e0b1ab784eff6835e73536bb9be740addbd7ec880
-
SHA512
50eabbc5bfb4a7c0e08390bffcaf72142bb9f462aa3a1d34d4091264a1ad1d1fe3f739d345f1d10fba31fc88cfb9b76525beb4e4b1e9857ea88c4f9cc6770a71
-
SSDEEP
1536:ibsZteviem9NOT8WbUPmo7kq5ZKtvE4IQTPvQrZT2GouxsBzPFSN9xNJ8z:ibMteqD6UPPQq5ZIftPKyGgZSvx/8z
Malware Config
Signatures
-
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 1612 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 3 IoCs
Processes:
AcroRd32.exepid process 1612 AcroRd32.exe 1612 AcroRd32.exe 1612 AcroRd32.exe
Processes
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\dc0a14b6_OpenFileToGetAccount30004302041006b.pdf"1⤵
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5c1b9121cfab030fb6a29458683021f08
SHA1b3c2dac10dc46147130000de2d0c7f274ee5e93e
SHA256dbeb5cf8142d48312b6b8be5d3814b3e25bca6dd7fcdb794ef5e1722af44c9ee
SHA5125dbfb70999807e71e804c1ac67f2ad3939b2dcfe6ef945449486fb188933a6df51d140e1a02eb82acb46a6699dac16d897958612539b88a3ddfd91a62e417fff