Analysis

  • max time kernel
    384s
  • max time network
    447s
  • platform
    windows10-1703_x64
  • resource
    win10-20240404-en
  • resource tags

    arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system
  • submitted
    30-06-2024 18:26

General

  • Target

    jre/lib/resources.jar

  • Size

    3.3MB

  • MD5

    9a084b91667e7437574236cd27b7c688

  • SHA1

    d8926cc4aa12d6fe9abe64c8c3cb8bc0f594c5b1

  • SHA256

    a1366a75454fc0f1ca5a14ea03b4927bb8584d6d5b402dfa453122ae16dbf22d

  • SHA512

    d603aa29e1f6eefff4b15c7ebc8a0fa18e090d2e1147d56fd80581c7404ee1cb9d6972fcf2bd0cb24926b3af4dfc5be9bce1fe018681f22a38adaa278bf22d73

  • SSDEEP

    49152:WX4zfeUcKDQ1toKXiO3fLxqhH3YRazQwIK7XgnyRMvMtMm55HopLKbtJzUkMkOBV:GL

Score
7/10

Malware Config

Signatures

  • Modifies file permissions 1 TTPs 1 IoCs
  • Suspicious use of WriteProcessMemory 2 IoCs

Processes

  • C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe
    java -jar C:\Users\Admin\AppData\Local\Temp\jre\lib\resources.jar
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:600
    • C:\Windows\system32\icacls.exe
      C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
      2⤵
      • Modifies file permissions
      PID:3076

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
    Filesize

    46B

    MD5

    bcd71065dd519457994001b4adc1d26b

    SHA1

    e6a2e6f4b5b2a29ba3db234ee50f427ea87ecf64

    SHA256

    4962c73dbed3c74eea2aca7605f480bae3714909b7f59ff78a8e31d8e45275fa

    SHA512

    e880af3dae2bd69625a73be991ad5e01bfdfd7f77aae7e891ede301484b921cde8659589352049ab82adfa5888eee1c89bce65618c3b811076d0f9cb3cec58f1

  • memory/600-2-0x0000026B8FE10000-0x0000026B90080000-memory.dmp
    Filesize

    2.4MB

  • memory/600-12-0x0000026B8E460000-0x0000026B8E461000-memory.dmp
    Filesize

    4KB

  • memory/600-13-0x0000026B8FE10000-0x0000026B90080000-memory.dmp
    Filesize

    2.4MB