Analysis
-
max time kernel
119s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 21:10
Behavioral task
behavioral1
Sample
Umbral.builder.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
Umbral.builder.exe
Resource
win10v2004-20240508-en
General
-
Target
Umbral.builder.exe
-
Size
114KB
-
MD5
d91fb6867df7e4303d98b5e90faae73c
-
SHA1
496f53ad8cd9381f1c1b577a73e978081002c1db
-
SHA256
bb19b002df31e1196b4e6530cf54c449e9cf1383d3adc5334a0442fa96b36344
-
SHA512
5dbcfe9bf567c6f1e18027950726af1835ab8b363ba8b040fd379b4cfe94b0894bc969b3c04fa4f1964b441a7b894bd4d37f3aabe3ea31396687a6ca093cfdc9
-
SSDEEP
3072:aumr2q8XTs/8wEQuKqAFCq8FBJGgMMlpVFPo6QoJ7j:aumr2q8XTs/8wEQJhCqbsVehy7
Malware Config
Signatures
-
Obfuscated with Agile.Net obfuscator 8 IoCs
Detects use of the Agile.Net commercial obfuscator, which is capable of entity renaming and control flow obfuscation.
Processes:
resource yara_rule behavioral1/memory/2416-2-0x0000000000490000-0x00000000004B0000-memory.dmp agile_net behavioral1/memory/2416-3-0x00000000004B0000-0x00000000004D0000-memory.dmp agile_net behavioral1/memory/2416-4-0x0000000000690000-0x00000000006FE000-memory.dmp agile_net behavioral1/memory/2416-6-0x00000000004D0000-0x00000000004DE000-memory.dmp agile_net behavioral1/memory/2416-7-0x0000000000850000-0x00000000008AA000-memory.dmp agile_net behavioral1/memory/2416-8-0x00000000004E0000-0x00000000004F0000-memory.dmp agile_net behavioral1/memory/2416-9-0x00000000004F0000-0x000000000050E000-memory.dmp agile_net behavioral1/memory/2416-10-0x000000001B9B0000-0x000000001BAFA000-memory.dmp agile_net -
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
Umbral.builder.exepid process 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe 2416 Umbral.builder.exe -
Suspicious use of AdjustPrivilegeToken 1 IoCs
Processes:
Umbral.builder.exedescription pid process Token: SeDebugPrivilege 2416 Umbral.builder.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/2416-0-0x000007FEF5FB3000-0x000007FEF5FB4000-memory.dmpFilesize
4KB
-
memory/2416-1-0x00000000008C0000-0x00000000008E2000-memory.dmpFilesize
136KB
-
memory/2416-2-0x0000000000490000-0x00000000004B0000-memory.dmpFilesize
128KB
-
memory/2416-3-0x00000000004B0000-0x00000000004D0000-memory.dmpFilesize
128KB
-
memory/2416-4-0x0000000000690000-0x00000000006FE000-memory.dmpFilesize
440KB
-
memory/2416-5-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-6-0x00000000004D0000-0x00000000004DE000-memory.dmpFilesize
56KB
-
memory/2416-7-0x0000000000850000-0x00000000008AA000-memory.dmpFilesize
360KB
-
memory/2416-8-0x00000000004E0000-0x00000000004F0000-memory.dmpFilesize
64KB
-
memory/2416-9-0x00000000004F0000-0x000000000050E000-memory.dmpFilesize
120KB
-
memory/2416-10-0x000000001B9B0000-0x000000001BAFA000-memory.dmpFilesize
1.3MB
-
memory/2416-11-0x000000001BB00000-0x000000001BC16000-memory.dmpFilesize
1.1MB
-
memory/2416-12-0x0000000000700000-0x0000000000730000-memory.dmpFilesize
192KB
-
memory/2416-13-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-14-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-15-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-16-0x000007FEF5FB3000-0x000007FEF5FB4000-memory.dmpFilesize
4KB
-
memory/2416-17-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-18-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB
-
memory/2416-19-0x000007FEF5FB0000-0x000007FEF699C000-memory.dmpFilesize
9.9MB