Analysis

  • max time kernel
    121s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    30-06-2024 19:30

General

  • Target

    209d99ef61d29924498d4f2dd40b3a6259f250f128f97655f7ddc5a77952439e.exe

  • Size

    731KB

  • MD5

    0bddfd060b57fd8e93a797e7e4d27ee9

  • SHA1

    e77ce1ee9f2f5d3829d356ddf240f8ec14129847

  • SHA256

    209d99ef61d29924498d4f2dd40b3a6259f250f128f97655f7ddc5a77952439e

  • SHA512

    3b5aec95563911370c9556bc0f159a3c0c52b5a323e53033bf7aef60ac68bcc96079cd91423a749cd1dc368fe944013256fb32bbc804ffb625e416213cd30106

  • SSDEEP

    6144:Fp19SmYRZbsuSBs3ojpe6aABlwZFsr5pOGJr3eRqk3tJc+xZRtiKzvzaOKIeM874:Fp1EPZbsu2s3ojpe6aeSg3DeRqkUWb

Score
1/10

Malware Config

Signatures

  • Suspicious use of WriteProcessMemory 3 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\209d99ef61d29924498d4f2dd40b3a6259f250f128f97655f7ddc5a77952439e.exe
    "C:\Users\Admin\AppData\Local\Temp\209d99ef61d29924498d4f2dd40b3a6259f250f128f97655f7ddc5a77952439e.exe"
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:2244
    • C:\Windows\system32\WerFault.exe
      C:\Windows\system32\WerFault.exe -u -p 2244 -s 76
      2⤵
        PID:2824

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads