Overview
overview
10Static
static
3CrystalDec...ed.dll
windows10-1703-x64
1KFlauncher.exe
windows10-1703-x64
10PROPAMAT/A...rk.dll
windows10-1703-x64
1PROPAMAT/C...et.dll
windows10-1703-x64
1PROPAMAT/C...ne.dll
windows10-1703-x64
1PROPAMAT/C...ce.dll
windows10-1703-x64
1PROPAMAT/C...ms.dll
windows10-1703-x64
1PROPAMAT/E_Mail.dll
windows10-1703-x64
1PROPAMAT/E_Net.dll
windows10-1703-x64
1PROPAMAT/FlDTE.dll
windows10-1703-x64
1PROPAMAT/F...on.dll
windows10-1703-x64
1PROPAMAT/F...on.dll
windows10-1703-x64
1PROPAMAT/F...PE.dll
windows10-1703-x64
1PROPAMAT/F...es.dll
windows10-1703-x64
1PROPAMAT/F...PE.dll
windows10-1703-x64
1PROPAMAT/F...nt.dll
windows10-1703-x64
1PROPAMAT/F...rk.dll
windows10-1703-x64
1jre/lib/ex...rn.jar
windows10-1703-x64
7jre/lib/ext/sunec.jar
windows10-1703-x64
7jre/lib/ex...er.jar
windows10-1703-x64
7jre/lib/ex...11.jar
windows10-1703-x64
7jre/lib/javaws.jar
windows10-1703-x64
7jre/lib/jce.jar
windows10-1703-x64
7jre/lib/jfr.jar
windows10-1703-x64
7jre/lib/jfxswt.jar
windows10-1703-x64
7jre/lib/jsse.jar
windows10-1703-x64
7jre/lib/ma...nt.jar
windows10-1703-x64
7jre/lib/plugin.jar
windows10-1703-x64
7jre/lib/resources.jar
windows10-1703-x64
7jre/lib/rt.jar
windows10-1703-x64
7jre/lib/se...cy.jar
windows10-1703-x64
7jre/lib/se...cy.jar
windows10-1703-x64
7Analysis
-
max time kernel
308s -
max time network
402s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
30-06-2024 18:26
Static task
static1
Behavioral task
behavioral1
Sample
CrystalDecisions.Shared.dll
Resource
win10-20240404-en
Behavioral task
behavioral2
Sample
KFlauncher.exe
Resource
win10-20240404-en
Behavioral task
behavioral3
Sample
PROPAMAT/AxInterop.XtremeSkinFramework.dll
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
PROPAMAT/ChilkatDotNet.dll
Resource
win10-20240404-en
Behavioral task
behavioral5
Sample
PROPAMAT/CrystalDecisions.CrystalReports.Engine.dll
Resource
win10-20240404-en
Behavioral task
behavioral6
Sample
PROPAMAT/CrystalDecisions.ReportSource.dll
Resource
win10-20240404-en
Behavioral task
behavioral7
Sample
PROPAMAT/CrystalDecisions.Windows.Forms.dll
Resource
win10-20240611-en
Behavioral task
behavioral8
Sample
PROPAMAT/E_Mail.dll
Resource
win10-20240404-en
Behavioral task
behavioral9
Sample
PROPAMAT/E_Net.dll
Resource
win10-20240404-en
Behavioral task
behavioral10
Sample
PROPAMAT/FlDTE.dll
Resource
win10-20240404-en
Behavioral task
behavioral11
Sample
PROPAMAT/FlDTEAutomatizacion.dll
Resource
win10-20240404-en
Behavioral task
behavioral12
Sample
PROPAMAT/FlDTEImpresion.dll
Resource
win10-20240404-en
Behavioral task
behavioral13
Sample
PROPAMAT/FlDTEImpresionPE.dll
Resource
win10-20240404-en
Behavioral task
behavioral14
Sample
PROPAMAT/FlDTEServices.dll
Resource
win10-20240611-en
Behavioral task
behavioral15
Sample
PROPAMAT/FlDTEServicesLibrosPE.dll
Resource
win10-20240404-en
Behavioral task
behavioral16
Sample
PROPAMAT/FlFramework.FlExceptionManagement.dll
Resource
win10-20240404-en
Behavioral task
behavioral17
Sample
PROPAMAT/FlFramework.dll
Resource
win10-20240404-en
Behavioral task
behavioral18
Sample
jre/lib/ext/nashorn.jar
Resource
win10-20240404-en
Behavioral task
behavioral19
Sample
jre/lib/ext/sunec.jar
Resource
win10-20240404-en
Behavioral task
behavioral20
Sample
jre/lib/ext/sunjce_provider.jar
Resource
win10-20240404-en
Behavioral task
behavioral21
Sample
jre/lib/ext/sunpkcs11.jar
Resource
win10-20240611-en
Behavioral task
behavioral22
Sample
jre/lib/javaws.jar
Resource
win10-20240404-en
Behavioral task
behavioral23
Sample
jre/lib/jce.jar
Resource
win10-20240404-en
Behavioral task
behavioral24
Sample
jre/lib/jfr.jar
Resource
win10-20240404-en
Behavioral task
behavioral25
Sample
jre/lib/jfxswt.jar
Resource
win10-20240404-en
Behavioral task
behavioral26
Sample
jre/lib/jsse.jar
Resource
win10-20240404-en
Behavioral task
behavioral27
Sample
jre/lib/management-agent.jar
Resource
win10-20240404-en
Behavioral task
behavioral28
Sample
jre/lib/plugin.jar
Resource
win10-20240611-en
Behavioral task
behavioral29
Sample
jre/lib/resources.jar
Resource
win10-20240404-en
Behavioral task
behavioral30
Sample
jre/lib/rt.jar
Resource
win10-20240404-en
Behavioral task
behavioral31
Sample
jre/lib/security/US_export_policy.jar
Resource
win10-20240404-en
Behavioral task
behavioral32
Sample
jre/lib/security/local_policy.jar
Resource
win10-20240404-en
General
-
Target
jre/lib/ext/nashorn.jar
-
Size
1.9MB
-
MD5
f3e3e7769994c69dff6e35ef938443ca
-
SHA1
758f42c0a03121ad980dc98be82dcaf790679e79
-
SHA256
cf0268ff39d19876bd42bf59e2ce93bb9aa57e5ee98c212bae0184bd87f2d35a
-
SHA512
ab4801e8538b9b84124d2b8c36e64232f16da686c5fa565c5de2091c910806a850464f5ccc79c9320df6f8cb943633fc38fea63f9e0593a44e3541f15f126951
-
SSDEEP
49152:fBkB7GOrPDSz0fHaIU1KDWtHkLs0amlyYu:fBkoOruSHa/4y/FmA
Malware Config
Signatures
-
Modifies file permissions 1 TTPs 1 IoCs
-
Suspicious use of WriteProcessMemory 2 IoCs
Processes:
java.exedescription pid process target process PID 2384 wrote to memory of 4844 2384 java.exe icacls.exe PID 2384 wrote to memory of 4844 2384 java.exe icacls.exe
Processes
-
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exejava -jar C:\Users\Admin\AppData\Local\Temp\jre\lib\ext\nashorn.jar1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\icacls.exeC:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M2⤵
- Modifies file permissions
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestampFilesize
46B
MD566dc520b0e7d200e26bd500e403f2396
SHA1d6d964d492e53675158522540a20f172fb8dda99
SHA256ce3ef3bc2bccb297f50882b5a02ff859a4fe205be1cdbbd3ce56a1f04d4ce3d9
SHA512de29cc0b2b74c71cc83b9bd8ec968b78d0160391040d71f128eaecd2db7ec10e1a60b2e416898609463e195829e8a42e7dc1d41423fefe183849b2a1fcf3dc2c
-
memory/2384-34-0x000002D4319F0000-0x000002D431A00000-memory.dmpFilesize
64KB
-
memory/2384-47-0x000002D4319E0000-0x000002D4319F0000-memory.dmpFilesize
64KB
-
memory/2384-14-0x000002D431960000-0x000002D431970000-memory.dmpFilesize
64KB
-
memory/2384-17-0x000002D431970000-0x000002D431980000-memory.dmpFilesize
64KB
-
memory/2384-18-0x000002D431980000-0x000002D431990000-memory.dmpFilesize
64KB
-
memory/2384-21-0x000002D431990000-0x000002D4319A0000-memory.dmpFilesize
64KB
-
memory/2384-22-0x000002D4319A0000-0x000002D4319B0000-memory.dmpFilesize
64KB
-
memory/2384-30-0x000002D4319D0000-0x000002D4319E0000-memory.dmpFilesize
64KB
-
memory/2384-29-0x000002D4319E0000-0x000002D4319F0000-memory.dmpFilesize
64KB
-
memory/2384-28-0x000002D4319C0000-0x000002D4319D0000-memory.dmpFilesize
64KB
-
memory/2384-48-0x000002D4319D0000-0x000002D4319E0000-memory.dmpFilesize
64KB
-
memory/2384-12-0x000002D42FE30000-0x000002D42FE31000-memory.dmpFilesize
4KB
-
memory/2384-35-0x000002D4316F0000-0x000002D431960000-memory.dmpFilesize
2.4MB
-
memory/2384-36-0x000002D431A00000-0x000002D431A10000-memory.dmpFilesize
64KB
-
memory/2384-37-0x000002D431A10000-0x000002D431A20000-memory.dmpFilesize
64KB
-
memory/2384-40-0x000002D431960000-0x000002D431970000-memory.dmpFilesize
64KB
-
memory/2384-41-0x000002D431970000-0x000002D431980000-memory.dmpFilesize
64KB
-
memory/2384-42-0x000002D431980000-0x000002D431990000-memory.dmpFilesize
64KB
-
memory/2384-43-0x000002D431990000-0x000002D4319A0000-memory.dmpFilesize
64KB
-
memory/2384-44-0x000002D4319A0000-0x000002D4319B0000-memory.dmpFilesize
64KB
-
memory/2384-45-0x000002D4319B0000-0x000002D4319C0000-memory.dmpFilesize
64KB
-
memory/2384-2-0x000002D4316F0000-0x000002D431960000-memory.dmpFilesize
2.4MB
-
memory/2384-46-0x000002D4319C0000-0x000002D4319D0000-memory.dmpFilesize
64KB
-
memory/2384-27-0x000002D4319B0000-0x000002D4319C0000-memory.dmpFilesize
64KB