�� R�9�`��~�����wKP�oS<���U�����5˕���?INX&�8�X<�x.<������/`"2+9;�W���l*xU Uh��B\�1��-{�Ú.v��g�Gf`:��h-�۽#�l��ͥf����rW�3�wS���$V���>,$?�3�X�Y*r�-��2��p�ِQhC�9莢�H �ԃ/\}�T<Rx����3V�R(�]pen����*n�o�b�qF���Tȕ*�4M�@f�GZ�͎��?e���G0i��'���ٖpc��"�i�%�to�r�QU��,B�:� �w/�#U�7G�J���Au����l ٚoA��.���:�E�<���d{�ld�"ږ��=�1�[�� Q�q��ΰ*�t��Mt��|�&+��x|�vi: ��5��F�����L �K}�\�x?�Ԟk����-�r��0�~c��K��yz�PH�ν��۩=�&Ѐ�ܶn�UY#Ypl1���N�� ���|ޕd2��Z���rI�W,r_\]��hR�)��o�H�~�;ݏ�<��e*��̰�q�(bQ���I�0ԇ�2���L�@���T$5�i�\) Vl�7[�n�G`f��oM�jD�|z`�F��A�XtC�1��ˇ99j6%BB��*~_�?Qʱ���r�eYv��_̙�A8�em&�Jh�KbX�����9��:��v��\�V��T�g�-�� g���h�P�dVu*H*�m���kœEzց��r����m��i�#p��~������ ��5��y����p�'<�_��nP���_Qc��>��`�n�K���O��Z��$,|ҹ��,s<�B�������L�0W8�4��/$��W�}&���w�RG����͈�Up��[�M�H�;�tS< ��ʿE�����*Wbp�:������#A��S}���u$�`B<��/Q��=7��sBF�@���熩'>�u(P6��Iw��o���^������َ�r��f�B�ϙ^�0{]��p��V����+�x����Hm��%�}'���(���+�>�#�@��?��>�9m2�i�~�pwxLH�/���ܫīفI�k�SO5K|۹��7�p'Ľ���B�D���WW�����y6�N���T���-��������p�����$�m>�Tǒ��!؞�®����Q�$F�b�o$:�g"�Z0��4���*�˃9[T����BB�D<�pVyFh)�8�i�L�:�5�xH,�4�V�t0���\�C��V<w�� |W%��R �\�h?3!���*`�꠵��Izw���o����qW0%9�X�L�7x���R���_.=��75�E�#�F�i�kh���,� P/�ݲz �\�<D�O45����x�U�H/�u��f\$�,Vɾ�b}�[�d���_5'7ۭw�a��?_��sЩ������:#���|�M'�nO"�@����a]e�z���~Y6Y6T6v�C�Y���z�FN�7}2�N3q)A'a�4�ր%9����ժ^"��8�@�yN�LiX��aY3A ���e{�^#����^�f�:z��I�ql�����rf��榷Iq��,=cy��curM_�(�vϧl����*W����5������_;�V\,��'�Wkp�hI���9n�vG�4�-��"�7C�͋����4R�_����ʵ��"��D�T�g���dJJ�%&�4�:X���z���G(�%�����ڂ�>��T�c0K� ��� t�����D!� �h�����*�N��B 8���\&�coQ"v��� �0.�^EI����e�����5�f�6�r!ċ�7;.�ޱ�� ݼZ�̸�zM$k�n�h��w����n|�=�WG���.��-�E���LcC�-Z��jJL��x��{�k�-?Z�G�9��r4�����#��?)�R�Y�?�S˱@���c��*��ǕSqL�^�B��(� ��vM=�ITw���W��Gc�Ù���%��ۑ�_M��I^�0�G�h��\�)< j�;�I���z��V��9<���}����kQ�EDb�L���|�C�%�8�E(͇݈���x/1(�ڡ&�7�fW* Z���h�E��� ��(T�;[�n6Ԡ_6��J���)RzQBj) �&�c�C�H��f���0���<�O�jJѻaav}V�K��t'xWXv���/�v�z�ϵ��d�-ν#�}�x��h֙��]�,*.� ���A�ɴʵ$��Z�g;�ᠢP�`�}�� T�<Sҿ:�q����p,��&W�VK2P�ן��qܑL���/Ì����Z�wk~�ȧ1�6l��zԊC\�X��qLL�T?6��<��B���0�J�D�'.?G�A$��o2���5�^!�s�g�=�=[?��+r���:`%��A�=%&b[���sWn,U%?��Ҕ=���on@��C)7�T}�� 1���,%OԱ ��ew)v��ۑ�<m��-<�����`�b�b��8�hD���eD���x #��\IV��}S��.6uZ"V��ĢM���f�W���^2�'H���b��� <��|'<��q���28��,B�&A� �,O�b6����>�b�@�'��ƌ6*��v��Z���[�Yߙֳ'�?U@�Ȫ��]Ǣo��Ԗ9�B�D���͝�$���{D_&�t���+O�b3�"Z��Ф�S��<������/��V!c�r�c#@��|b@T��7����Z 7Y�}=o��?�nEo ��r�yzr6�!� ����QDW-<kg@G��{�fT�@���� �Fm��D,v}�� " �����q*�(��`m3�ȝW(�)�ڞ��?r�� ��ɵ��qVR���\��D�f� �#�.�C�a�9 g.:�A��R���값-T�(k����L�kd��~���D��D1�u�|�'��̵\�v��OP�S�ў��� ����-��$�"�k o��(����ܲ|��<�j�}������Gq�߄˹@� I�d�9�����^I����������-g� Z� U~"�d r��i��Q&�������}�����>z�3i:��o�zǡ����}c(
Behavioral task
behavioral1
Sample
b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96.exe
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96.exe
Resource
win10v2004-20240611-en
General
-
Target
b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96
-
Size
7.5MB
-
MD5
c443e48d5d694f46ac75803502537d49
-
SHA1
77773230d0563684f6eb8640e67f4656c91de221
-
SHA256
b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96
-
SHA512
a585eeca37705dd910bcd7599f1bbb0de035d8a337d60e47c924a6d18cb02aab3934eee799726f5044b8d7b76eed8126766b0f3b625e2d3ac187c029f8fba1b9
-
SSDEEP
196608:JXQunepn0D07Gen6765oacIo70fN4BncsGD8:JXQuneODI6kdfW7P
Malware Config
Signatures
-
Processes:
resource yara_rule sample vmprotect -
Unsigned PE 1 IoCs
Checks for missing Authenticode signature.
Processes:
resource b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96
Files
-
b7312ca08230a2fd10619f8df39da6ec1bcaff14ab3f1eda2b833bcb40f6db96.exe windows:5 windows x86 arch:x86
2c60c7daf8c0d72826b53c09fe63703f
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
Imports
winmm
midiStreamOut
ws2_32
WSAAsyncSelect
kernel32
GetVersion
GetVersionExA
VirtualQuery
LocalAlloc
LocalFree
GetModuleFileNameW
GetProcessAffinityMask
SetProcessAffinityMask
SetThreadAffinityMask
Sleep
ExitProcess
FreeLibrary
LoadLibraryA
GetModuleHandleA
GetProcAddress
user32
GetWindow
GetProcessWindowStation
GetProcessWindowStation
GetUserObjectInformationW
gdi32
TextOutA
winspool.drv
OpenPrinterA
advapi32
RegOpenKeyExA
shell32
Shell_NotifyIconA
ole32
CLSIDFromString
oleaut32
LoadTypeLi
comctl32
ord17
comdlg32
ChooseColorA
wtsapi32
WTSSendMessageW
Exports
Exports
Sections
.text Size: - Virtual size: 592KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: - Virtual size: 6.3MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: - Virtual size: 204KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.vmp0 Size: - Virtual size: 2.6MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.vmp1 Size: 7.5MB - Virtual size: 7.5MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 16KB - Virtual size: 13KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ