Overview
overview
10Static
static
3CrystalDec...ed.dll
windows10-1703-x64
1KFlauncher.exe
windows10-1703-x64
10PROPAMAT/A...rk.dll
windows10-1703-x64
1PROPAMAT/C...et.dll
windows10-1703-x64
1PROPAMAT/C...ne.dll
windows10-1703-x64
1PROPAMAT/C...ce.dll
windows10-1703-x64
1PROPAMAT/C...ms.dll
windows10-1703-x64
1PROPAMAT/E_Mail.dll
windows10-1703-x64
1PROPAMAT/E_Net.dll
windows10-1703-x64
1PROPAMAT/FlDTE.dll
windows10-1703-x64
1PROPAMAT/F...on.dll
windows10-1703-x64
1PROPAMAT/F...on.dll
windows10-1703-x64
1PROPAMAT/F...PE.dll
windows10-1703-x64
1PROPAMAT/F...es.dll
windows10-1703-x64
1PROPAMAT/F...PE.dll
windows10-1703-x64
1PROPAMAT/F...nt.dll
windows10-1703-x64
1PROPAMAT/F...rk.dll
windows10-1703-x64
1jre/lib/ex...rn.jar
windows10-1703-x64
7jre/lib/ext/sunec.jar
windows10-1703-x64
7jre/lib/ex...er.jar
windows10-1703-x64
7jre/lib/ex...11.jar
windows10-1703-x64
7jre/lib/javaws.jar
windows10-1703-x64
7jre/lib/jce.jar
windows10-1703-x64
7jre/lib/jfr.jar
windows10-1703-x64
7jre/lib/jfxswt.jar
windows10-1703-x64
7jre/lib/jsse.jar
windows10-1703-x64
7jre/lib/ma...nt.jar
windows10-1703-x64
7jre/lib/plugin.jar
windows10-1703-x64
7jre/lib/resources.jar
windows10-1703-x64
7jre/lib/rt.jar
windows10-1703-x64
7jre/lib/se...cy.jar
windows10-1703-x64
7jre/lib/se...cy.jar
windows10-1703-x64
7Analysis
-
max time kernel
384s -
max time network
447s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
30-06-2024 18:26
Static task
static1
Behavioral task
behavioral1
Sample
CrystalDecisions.Shared.dll
Resource
win10-20240404-en
Behavioral task
behavioral2
Sample
KFlauncher.exe
Resource
win10-20240404-en
Behavioral task
behavioral3
Sample
PROPAMAT/AxInterop.XtremeSkinFramework.dll
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
PROPAMAT/ChilkatDotNet.dll
Resource
win10-20240404-en
Behavioral task
behavioral5
Sample
PROPAMAT/CrystalDecisions.CrystalReports.Engine.dll
Resource
win10-20240404-en
Behavioral task
behavioral6
Sample
PROPAMAT/CrystalDecisions.ReportSource.dll
Resource
win10-20240404-en
Behavioral task
behavioral7
Sample
PROPAMAT/CrystalDecisions.Windows.Forms.dll
Resource
win10-20240611-en
Behavioral task
behavioral8
Sample
PROPAMAT/E_Mail.dll
Resource
win10-20240404-en
Behavioral task
behavioral9
Sample
PROPAMAT/E_Net.dll
Resource
win10-20240404-en
Behavioral task
behavioral10
Sample
PROPAMAT/FlDTE.dll
Resource
win10-20240404-en
Behavioral task
behavioral11
Sample
PROPAMAT/FlDTEAutomatizacion.dll
Resource
win10-20240404-en
Behavioral task
behavioral12
Sample
PROPAMAT/FlDTEImpresion.dll
Resource
win10-20240404-en
Behavioral task
behavioral13
Sample
PROPAMAT/FlDTEImpresionPE.dll
Resource
win10-20240404-en
Behavioral task
behavioral14
Sample
PROPAMAT/FlDTEServices.dll
Resource
win10-20240611-en
Behavioral task
behavioral15
Sample
PROPAMAT/FlDTEServicesLibrosPE.dll
Resource
win10-20240404-en
Behavioral task
behavioral16
Sample
PROPAMAT/FlFramework.FlExceptionManagement.dll
Resource
win10-20240404-en
Behavioral task
behavioral17
Sample
PROPAMAT/FlFramework.dll
Resource
win10-20240404-en
Behavioral task
behavioral18
Sample
jre/lib/ext/nashorn.jar
Resource
win10-20240404-en
Behavioral task
behavioral19
Sample
jre/lib/ext/sunec.jar
Resource
win10-20240404-en
Behavioral task
behavioral20
Sample
jre/lib/ext/sunjce_provider.jar
Resource
win10-20240404-en
Behavioral task
behavioral21
Sample
jre/lib/ext/sunpkcs11.jar
Resource
win10-20240611-en
Behavioral task
behavioral22
Sample
jre/lib/javaws.jar
Resource
win10-20240404-en
Behavioral task
behavioral23
Sample
jre/lib/jce.jar
Resource
win10-20240404-en
Behavioral task
behavioral24
Sample
jre/lib/jfr.jar
Resource
win10-20240404-en
Behavioral task
behavioral25
Sample
jre/lib/jfxswt.jar
Resource
win10-20240404-en
Behavioral task
behavioral26
Sample
jre/lib/jsse.jar
Resource
win10-20240404-en
Behavioral task
behavioral27
Sample
jre/lib/management-agent.jar
Resource
win10-20240404-en
Behavioral task
behavioral28
Sample
jre/lib/plugin.jar
Resource
win10-20240611-en
Behavioral task
behavioral29
Sample
jre/lib/resources.jar
Resource
win10-20240404-en
Behavioral task
behavioral30
Sample
jre/lib/rt.jar
Resource
win10-20240404-en
Behavioral task
behavioral31
Sample
jre/lib/security/US_export_policy.jar
Resource
win10-20240404-en
Behavioral task
behavioral32
Sample
jre/lib/security/local_policy.jar
Resource
win10-20240404-en
General
-
Target
jre/lib/resources.jar
-
Size
3.3MB
-
MD5
9a084b91667e7437574236cd27b7c688
-
SHA1
d8926cc4aa12d6fe9abe64c8c3cb8bc0f594c5b1
-
SHA256
a1366a75454fc0f1ca5a14ea03b4927bb8584d6d5b402dfa453122ae16dbf22d
-
SHA512
d603aa29e1f6eefff4b15c7ebc8a0fa18e090d2e1147d56fd80581c7404ee1cb9d6972fcf2bd0cb24926b3af4dfc5be9bce1fe018681f22a38adaa278bf22d73
-
SSDEEP
49152:WX4zfeUcKDQ1toKXiO3fLxqhH3YRazQwIK7XgnyRMvMtMm55HopLKbtJzUkMkOBV:GL
Malware Config
Signatures
-
Modifies file permissions 1 TTPs 1 IoCs
-
Suspicious use of WriteProcessMemory 2 IoCs
Processes:
java.exedescription pid process target process PID 600 wrote to memory of 3076 600 java.exe icacls.exe PID 600 wrote to memory of 3076 600 java.exe icacls.exe
Processes
-
C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exejava -jar C:\Users\Admin\AppData\Local\Temp\jre\lib\resources.jar1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\icacls.exeC:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M2⤵
- Modifies file permissions
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestampFilesize
46B
MD5bcd71065dd519457994001b4adc1d26b
SHA1e6a2e6f4b5b2a29ba3db234ee50f427ea87ecf64
SHA2564962c73dbed3c74eea2aca7605f480bae3714909b7f59ff78a8e31d8e45275fa
SHA512e880af3dae2bd69625a73be991ad5e01bfdfd7f77aae7e891ede301484b921cde8659589352049ab82adfa5888eee1c89bce65618c3b811076d0f9cb3cec58f1
-
memory/600-2-0x0000026B8FE10000-0x0000026B90080000-memory.dmpFilesize
2.4MB
-
memory/600-12-0x0000026B8E460000-0x0000026B8E461000-memory.dmpFilesize
4KB
-
memory/600-13-0x0000026B8FE10000-0x0000026B90080000-memory.dmpFilesize
2.4MB