Overview
overview
4Static
static
1URLScan
urlscan
1https://stopify.co/f...
windows10-2004-x64
1https://stopify.co/f...
windows7-x64
1https://stopify.co/f...
windows10-1703-x64
4https://stopify.co/f...
windows10-2004-x64
1https://stopify.co/f...
windows11-21h2-x64
1https://stopify.co/f...
android-9-x86
1https://stopify.co/f...
android-10-x64
1https://stopify.co/f...
android-11-x64
1https://stopify.co/f...
android-13-x64
1https://stopify.co/f...
android-9-x86
1https://stopify.co/f...
macos-10.15-amd64
1https://stopify.co/f...
macos-10.15-amd64
4https://stopify.co/f...
ubuntu-24.04-amd64
4https://stopify.co/f...
debian-12-armhf
https://stopify.co/f...
debian-12-mipsel
https://stopify.co/f...
debian-9-armhf
https://stopify.co/f...
debian-9-mips
https://stopify.co/f...
debian-9-mipsel
https://stopify.co/f...
ubuntu-18.04-amd64
3https://stopify.co/f...
ubuntu-20.04-amd64
4https://stopify.co/f...
ubuntu-22.04-amd64
3https://stopify.co/f...
ubuntu-24.04-amd64
4Analysis
-
max time kernel
1799s -
max time network
1608s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
30-06-2024 16:21
Static task
static1
URLScan task
urlscan1
Behavioral task
behavioral1
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
win10v2004-20240508-en
Behavioral task
behavioral2
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
win7-20240508-en
Behavioral task
behavioral3
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
win11-20240611-en
Behavioral task
behavioral6
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
android-x86-arm-20240624-en
Behavioral task
behavioral7
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
android-x64-20240624-en
Behavioral task
behavioral8
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
android-x64-arm64-20240624-en
Behavioral task
behavioral9
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
android-33-x64-arm64-20240624-en
Behavioral task
behavioral10
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
android-x86-arm-20240624-en
Behavioral task
behavioral11
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
macos-20240611-en
Behavioral task
behavioral12
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
macos-20240611-en
Behavioral task
behavioral13
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral14
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
debian12-armhf-20240418-en
Behavioral task
behavioral15
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
debian12-mipsel-20240221-en
Behavioral task
behavioral16
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
debian9-armhf-20240418-en
Behavioral task
behavioral17
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral18
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
debian9-mipsel-20240611-en
Behavioral task
behavioral19
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral20
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
ubuntu2004-amd64-20240508-en
Behavioral task
behavioral21
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
ubuntu2204-amd64-20240522.1-en
Behavioral task
behavioral22
Sample
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Resource
ubuntu2404-amd64-20240523-en
General
-
Target
https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com
Malware Config
Signatures
-
Drops file in Windows directory 4 IoCs
Processes:
MicrosoftEdgeCP.exeMicrosoftEdge.exeMicrosoftEdgeCP.exedescription ioc process File created C:\Windows\rescache\_merged\3720402701\1568373884.pri MicrosoftEdgeCP.exe File created C:\Windows\rescache\_merged\3720402701\1568373884.pri MicrosoftEdge.exe File opened for modification C:\Windows\Debug\ESE.TXT MicrosoftEdge.exe File created C:\Windows\rescache\_merged\3720402701\1568373884.pri MicrosoftEdgeCP.exe -
Processes:
browser_broker.exeMicrosoftEdgeCP.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000\Software\Microsoft\Internet Explorer\Main browser_broker.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000\Software\Microsoft\Internet Explorer\Main MicrosoftEdgeCP.exe -
Modifies registry class 64 IoCs
Processes:
MicrosoftEdge.exeMicrosoftEdgeCP.exeMicrosoftEdgeCP.exeMicrosoftEdgeCP.exeMicrosoftEdgeCP.exedescription ioc process Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\BrowserEmulation\CVListXMLVersionLow = "0" MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\VendorId = "0" MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\Wow64-VersionHigh = "0" MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Rating MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\Wow64-VersionLow = "0" MicrosoftEdge.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\CIStatus\CIStatusTimestamp = 342bdab109cbda01 MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\006\ACGStatus MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\DomainSuggestion\NextUpdateDate = "426529474" MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\grabify.link\NumberOfSubdoma = "0" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates MicrosoftEdge.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\CIStatus\SignaturePolicy = 06000000 MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\CIStatus\CIStatusTimestamp = c8dd1d9709cbda01 MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Internet Explorer\Main MicrosoftEdge.exe Set value (str) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\Internet Settings\Cache\Cookies\CachePrefix = "Cookie:" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\HistoryJournalCertificate MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\grabify.link\ = "0" MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\CIStatus\CIStatusTimestamp = 0efe40b709cbda01 MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\CIStatus MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\Wow64-SubSysId = "0" MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\Internet Explorer\Main MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\HistoryJournalCertificate\CRLs MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\DeviceId = "0" MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\Internet Settings\Cache\Content\CacheLimit = "256000" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\HistoryJournalCertificate\Certificates MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FavOrder MicrosoftEdge.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Internet Settings\Zones\3\{A8A88C49-5EB2-4990-A1A2-08760 = 1a3761592352350c7a5f20172f1e1a190e2b017313371312141a152a MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\grabify.link\Total = "13" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Software\Microsoft\SystemCertificates\trust\Certificates MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Recovery\PendingRecovery\ReadingStorePending = "1" MicrosoftEdge.exe Set value (str) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\Internet Settings\Cache\History\CachePrefix = "Visited:" MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\Total\ = "288" MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\ACGStatus\DynamicCodePolicy = 05000000 MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\HistoryJournalCertificate\NextUpdateDate = "426546068" MicrosoftEdge.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Internet Settings\Zones\3\{AEBA21FA-782A-4A90-978D-B7216 = 1a3761592352350c7a5f20172f1e1a190e2b017313371312141a152a MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\Internet Settings\Cache\Content MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\CIStatus\CIStatusTimestamp = 173e3f9709cbda01 MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\DataStore MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\grabify.link\ = "288" MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead\Meta\generator$MediaWiki MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Software\Microsoft\SystemCertificates\Disallowed\Certificates MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Recovery\Active MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\CIStatus MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\grabify.link\Total = "288" MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\ACGStatus\ACGPolicyState = "8" MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead\Meta\generator$vBulletin 3 MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FavOrder\SyncIEFirstTimeFullScan = "1" MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\grabify.link MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\DataStore\LastCleanup = 50ae2da009cbda01 MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\grabify.link\Total = "621" MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Internet Settings\PrivacyAdvanced = "0" MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\004\Internet Settings\Cache\Cookies\CacheLimit = "1" MicrosoftEdgeCP.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\grabify.link\NumberOfSubd = "0" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Software\Microsoft\SystemCertificates\CA\CTLs MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\006\CIStatus MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Protected - It is a violation of Windows Policy to modif = 01000000c468649a7674191746dd2edba9fe8079cc8643d36a2a810a838b28af3984415a0c4639e59dfc3959e8e46f51616a632ac37808ec7fca046cb909 MicrosoftEdge.exe Set value (str) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\GPU\AdapterInfo = "vendorId=\"0x1414\",deviceID=\"0x8c\",subSysID=\"0x0\",revision=\"0x0\",version=\"10.0.15063.0\"hypervisor=\"No Hypervisor (No SLAT)\"" MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Software\Microsoft\SystemCertificates\trust\CTLs MicrosoftEdge.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\Total MicrosoftEdgeCP.exe Set value (data) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\CIStatus\SignaturePolicy = 06000000 MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\Internet Settings\Cache\Content MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\121\Internet Settings\Cache\Cookies MicrosoftEdgeCP.exe Key created \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\DomainSuggestion MicrosoftEdge.exe Set value (int) \REGISTRY\USER\S-1-5-21-3968772205-1713802336-1776639840-1000_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\006\CIStatus\CIPolicyState = "0" MicrosoftEdgeCP.exe -
Suspicious behavior: MapViewOfSection 4 IoCs
Processes:
MicrosoftEdgeCP.exepid process 1692 MicrosoftEdgeCP.exe 1692 MicrosoftEdgeCP.exe 1692 MicrosoftEdgeCP.exe 1692 MicrosoftEdgeCP.exe -
Suspicious use of AdjustPrivilegeToken 4 IoCs
Processes:
MicrosoftEdgeCP.exedescription pid process Token: SeDebugPrivilege 1588 MicrosoftEdgeCP.exe Token: SeDebugPrivilege 1588 MicrosoftEdgeCP.exe Token: SeDebugPrivilege 1588 MicrosoftEdgeCP.exe Token: SeDebugPrivilege 1588 MicrosoftEdgeCP.exe -
Suspicious use of SetWindowsHookEx 4 IoCs
Processes:
MicrosoftEdge.exeMicrosoftEdgeCP.exeMicrosoftEdgeCP.exepid process 2148 MicrosoftEdge.exe 1692 MicrosoftEdgeCP.exe 1588 MicrosoftEdgeCP.exe 1692 MicrosoftEdgeCP.exe -
Suspicious use of WriteProcessMemory 9 IoCs
Processes:
MicrosoftEdgeCP.exedescription pid process target process PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe PID 1692 wrote to memory of 4180 1692 MicrosoftEdgeCP.exe MicrosoftEdgeCP.exe
Processes
-
C:\Windows\system32\LaunchWinApp.exe"C:\Windows\system32\LaunchWinApp.exe" "https://stopify.co/film.php?idhttps://youtu.be/dQw4w9WgXcQ?si=PVZoxY1NY1sWsfwp=O6K4FC.com"1⤵
-
C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca1⤵
- Drops file in Windows directory
- Modifies registry class
- Suspicious use of SetWindowsHookEx
-
C:\Windows\system32\browser_broker.exeC:\Windows\system32\browser_broker.exe -Embedding1⤵
- Modifies Internet Explorer settings
-
C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe" -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca1⤵
- Modifies registry class
- Suspicious behavior: MapViewOfSection
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe" -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca1⤵
- Drops file in Windows directory
- Modifies Internet Explorer settings
- Modifies registry class
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of SetWindowsHookEx
-
C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe" -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca1⤵
- Drops file in Windows directory
- Modifies registry class
-
C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe" -ServerName:ContentProcess.AppX6z3cwk4fvgady6zya12j1cw28d228a7k.mca1⤵
- Modifies registry class
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157Filesize
4KB
MD51bfe591a4fe3d91b03cdf26eaacd8f89
SHA1719c37c320f518ac168c86723724891950911cea
SHA2569cf94355051bf0f4a45724ca20d1cc02f76371b963ab7d1e38bd8997737b13d8
SHA51202f88da4b610678c31664609bcfa9d61db8d0b0617649981af948f670f41a6207b4ec19fecce7385a24e0c609cbbf3f2b79a8acaf09a03c2c432cc4dce75e9db
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\E49JWOHD\edgecompatviewlist[1].xmlFilesize
74KB
MD5d4fc49dc14f63895d997fa4940f24378
SHA13efb1437a7c5e46034147cbbc8db017c69d02c31
SHA256853d2f4eb81c9fdcea2ee079f6faf98214b111b77cdf68709b38989d123890f1
SHA512cc60d79b4afe5007634ac21dc4bc92081880be4c0d798a1735b63b27e936c02f399964f744dc73711987f01e8a1064b02a4867dd6cac27538e5fbe275cc61e0a
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\2IYNGM9T\min-widget[1].cssFilesize
24KB
MD585bc05ac9c8cf96b380e0ae1866aaadf
SHA129355251295c8610c7ff032d8252d94987adc8a9
SHA2561dbc2527f5f9662d10909d5a818c5d50b12f128df778f041ecfc5d438815c8d9
SHA5121e000e02ef0715d72e834acfbdf866ece88454bd83ef22900d50504bf260c7aaf133a620e595ce22f933683bb1c6fc93126ad053f2fc6cb426f9b4873c889744
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\User\Default\DOMStore\36RB6LTF\grabify[1].xmlFilesize
13B
MD5c1ddea3ef6bbef3e7060a1a9ad89e4c5
SHA135e3224fcbd3e1af306f2b6a2c6bbea9b0867966
SHA256b71e4d17274636b97179ba2d97c742735b6510eb54f22893d3a2daff2ceb28db
SHA5126be8cec7c862afae5b37aa32dc5bb45912881a3276606da41bf808a4ef92c318b355e616bf45a257b995520d72b7c08752c0be445dceade5cf79f73480910fed
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\User\Default\DOMStore\36RB6LTF\grabify[1].xmlFilesize
261B
MD50c9c0b316fe3fe828f773987c61c44f2
SHA1cc169d705e1010359c82d1ef81b9b4240ad47e8d
SHA2564d3f2298ca0aaca3da32ec90edfb6b22c0b63c12bff7198b894568c8a567702f
SHA5122c176557624bab1d7f7dd2b9303a515e088ae206f5b252b58af2d2579f796bf2a74dbd4d508cbf2819fc17866a6ae2abaad7d14afbecd8e5741cb9567828f8c0
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\User\Default\DOMStore\36RB6LTF\grabify[1].xmlFilesize
1KB
MD5065cf087258edf872dba8687be82fb74
SHA1409a2efe3239c73f1c843536fae7c45cb114b563
SHA2568fadb334ba7f6cfb0c0506409bea02cc5d35da9a3b97be9d6e55e25a4918179e
SHA51239ad349698e0f4e1ca383f61ba1f872279c9ef313a58e8117ffa1ba4f68a0f419c4e64c6c2e7ce5f02a570a4dcbed213cc94c290b5c272edf23bca79b6492979
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache\07W2M6B6\favicon[1].svgFilesize
2KB
MD5a64f390468963fe1d8da38911fbd579d
SHA145e7c35f78af97f1a905cf392393c82d5678a214
SHA2561b941abb7847b5e898bebd984a3c3a50a1d61bab412f095fd99d0a76d2a7b320
SHA512cad7456f5e35873140be2cc1cbb2f6395a179e7dd3ea5b9648d320653116104ff4849a357ed9374daf820a495894d33084d46335bd938edb6a5b7de3695de664
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache\07W2M6B6\suggestions[1].en-USFilesize
17KB
MD55a34cb996293fde2cb7a4ac89587393a
SHA13c96c993500690d1a77873cd62bc639b3a10653f
SHA256c6a5377cbc07eece33790cfc70572e12c7a48ad8296be25c0cc805a1f384dbad
SHA512e1b7d0107733f81937415104e70f68b1be6fd0ca65dccf4ff72637943d44278d3a77f704aedff59d2dbc0d56a609b2590c8ec0dd6bc48ab30f1dad0c07a0a3ee
-
C:\Users\Admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache\PX5M7N3R\200[1].pngFilesize
8KB
MD5603d42d3ec2ecae549f782fdf07b5d74
SHA1496d7af876abc32a520737e3ae20289c1aab1321
SHA25669d84f385d51724154fbdd35a5edb0e004f3fc880bdfb249476db0abe8d7cf2d
SHA5127ab227b941d4cac7e8c4070809141d34e21fafc86da2fcaf3ff7a6228e2d8cc14c29c94c83e9f5249594a9ebdec6e69cec1e905f13756fae06ba4d0d47f0ede3
-
memory/2148-298-0x000002848E280000-0x000002848E281000-memory.dmpFilesize
4KB
-
memory/2148-521-0x000002848E800000-0x000002848F6C2000-memory.dmpFilesize
14.8MB
-
memory/2148-16-0x0000028487720000-0x0000028487730000-memory.dmpFilesize
64KB
-
memory/2148-35-0x0000028486870000-0x0000028486872000-memory.dmpFilesize
8KB
-
memory/2148-299-0x000002848E290000-0x000002848E291000-memory.dmpFilesize
4KB
-
memory/2148-0-0x0000028487620000-0x0000028487630000-memory.dmpFilesize
64KB
-
memory/4180-375-0x00000222F7400000-0x00000222F7500000-memory.dmpFilesize
1024KB
-
memory/4180-416-0x00000222F5EC0000-0x00000222F5EC2000-memory.dmpFilesize
8KB
-
memory/4180-312-0x00000222F5870000-0x00000222F5890000-memory.dmpFilesize
128KB
-
memory/4180-363-0x00000222F5A70000-0x00000222F5A90000-memory.dmpFilesize
128KB
-
memory/4180-373-0x00000222F7400000-0x00000222F7500000-memory.dmpFilesize
1024KB
-
memory/4180-123-0x00000222F58B0000-0x00000222F58B2000-memory.dmpFilesize
8KB
-
memory/4180-117-0x00000222F54D0000-0x00000222F54D2000-memory.dmpFilesize
8KB
-
memory/4180-115-0x00000222F54B0000-0x00000222F54B2000-memory.dmpFilesize
8KB
-
memory/4180-413-0x00000222F5EB0000-0x00000222F5EB2000-memory.dmpFilesize
8KB
-
memory/4180-111-0x00000222F5490000-0x00000222F5492000-memory.dmpFilesize
8KB
-
memory/4180-65-0x00000222F3900000-0x00000222F3A00000-memory.dmpFilesize
1024KB
-
memory/4180-119-0x00000222F54F0000-0x00000222F54F2000-memory.dmpFilesize
8KB
-
memory/4180-121-0x00000222F57F0000-0x00000222F57F2000-memory.dmpFilesize
8KB
-
memory/4180-125-0x00000222F58D0000-0x00000222F58D2000-memory.dmpFilesize
8KB
-
memory/4180-778-0x00000222F3A00000-0x00000222F3A10000-memory.dmpFilesize
64KB
-
memory/4180-853-0x00000222F3A00000-0x00000222F3A10000-memory.dmpFilesize
64KB