Analysis
-
max time kernel
146s -
max time network
151s -
platform
windows11-21h2_x64 -
resource
win11-20240611-en -
resource tags
arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system -
submitted
30-06-2024 17:37
Static task
static1
Behavioral task
behavioral1
Sample
fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral2
Sample
fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f.exe
Resource
win11-20240611-en
General
-
Target
fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f.exe
-
Size
535KB
-
MD5
b865b44d5830929a37debc21a4769a1d
-
SHA1
af764c3e60c0d3db9fc117fc3d166a2e09908fd6
-
SHA256
fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f
-
SHA512
9f86ad6aed05f07b4571ea56ba2dd38b4761a78cc20bec33f8e67b8877feba5ce6b0ebf7ddb802b535e88c615f4fbce34299a3b87bb774954daecb261ee0a3be
-
SSDEEP
12288:txOY/DL2AHHiQhq6Ln16QhhJ1FbMcwj9R5dSJ67:7OQCkHiQQ6Ln168kl1QJc
Malware Config
Signatures
-
Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs
Bootkits write to the MBR to gain persistence at a level below the operating system.
Processes:
fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f.exedescription ioc process File opened for modification \??\PHYSICALDRIVE0 fbc66a718c78eac303e9b2fe47c2f1b32287482bd773b6cdb0f45cec6fc1ae5f.exe
Processes
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2376-3-0x0000000000400000-0x000000000046F000-memory.dmpFilesize
444KB
-
memory/2376-2-0x0000000002EA0000-0x0000000002F0B000-memory.dmpFilesize
428KB
-
memory/2376-1-0x0000000002F20000-0x0000000003020000-memory.dmpFilesize
1024KB
-
memory/2376-4-0x0000000000400000-0x0000000002C3F000-memory.dmpFilesize
40.2MB
-
memory/2376-5-0x0000000000400000-0x0000000002C3F000-memory.dmpFilesize
40.2MB
-
memory/2376-6-0x0000000002F20000-0x0000000003020000-memory.dmpFilesize
1024KB
-
memory/2376-8-0x0000000000400000-0x000000000046F000-memory.dmpFilesize
444KB