Analysis
-
max time kernel
120s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 18:23
Behavioral task
behavioral1
Sample
0686a70ec0e364d99c20e5d8715e3da431b16746d4d5a49a4891886b474cbe51.exe
Resource
win7-20240221-en
2 signatures
150 seconds
Behavioral task
behavioral2
Sample
0686a70ec0e364d99c20e5d8715e3da431b16746d4d5a49a4891886b474cbe51.exe
Resource
win10v2004-20240611-en
2 signatures
150 seconds
General
-
Target
0686a70ec0e364d99c20e5d8715e3da431b16746d4d5a49a4891886b474cbe51.exe
-
Size
6.5MB
-
MD5
248435ecca1107093a00e728b81a6841
-
SHA1
cbf54a2ce7fa90c2f95a027e4756bd5d10b2881f
-
SHA256
0686a70ec0e364d99c20e5d8715e3da431b16746d4d5a49a4891886b474cbe51
-
SHA512
1062792858a99bd4aea62d38a1852418a21bc635658a4689194fcc8303702601e90e23626e76bc6a0c9ee4883f8451108e0ab43af9ad530a52ec3846c31be73d
-
SSDEEP
98304:1JPJKH0CAr5T1nT8dzg4n3Mgh8aZ7qodU6ojm1L2Y9o9th8NydYs2HWFVkfG/fG:vR3rZWdzF3NfAYyctqth8JHWF2Gm
Score
9/10
Malware Config
Signatures
-
Detects executables packed with Themida 2 IoCs
Processes:
resource yara_rule behavioral1/memory/1968-0-0x0000000000400000-0x0000000001302000-memory.dmp INDICATOR_EXE_Packed_Themida behavioral1/memory/1968-1-0x0000000000400000-0x0000000001302000-memory.dmp INDICATOR_EXE_Packed_Themida -
Processes:
resource yara_rule behavioral1/memory/1968-0-0x0000000000400000-0x0000000001302000-memory.dmp themida behavioral1/memory/1968-1-0x0000000000400000-0x0000000001302000-memory.dmp themida