Analysis

  • max time kernel
    48s
  • max time network
    52s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 01:09

General

  • Target

    61b587387d7eb0bcd6096ba237b11a1c6932a11aa440123422fe9ea49773c8ac.exe

  • Size

    2.7MB

  • MD5

    ac49aa41a5551500d3b78db56c5ba720

  • SHA1

    f97816fdad7521097cbaa2830115aac079d9a6cd

  • SHA256

    61b587387d7eb0bcd6096ba237b11a1c6932a11aa440123422fe9ea49773c8ac

  • SHA512

    8627ceaa7753247ed52d2884347e212f1ca5c9149710dbbe798d5acccf9c3bd67e31385656ca37f68f065739b045eb973aad41aaabf26f97099c73b6bffb3904

  • SSDEEP

    49152:KhBiTCL3IpB+IkhRTWEqfCuXfJ216k4xIURehptc8:KhBiTCL3S+IkhRTWEqfn0FJEehp+8

Score
6/10

Malware Config

Signatures

  • Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs

    Bootkits write to the MBR to gain persistence at a level below the operating system.

  • Modifies registry class 11 IoCs
  • Suspicious use of FindShellTrayWindow 5 IoCs
  • Suspicious use of SendNotifyMessage 5 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\61b587387d7eb0bcd6096ba237b11a1c6932a11aa440123422fe9ea49773c8ac.exe
    "C:\Users\Admin\AppData\Local\Temp\61b587387d7eb0bcd6096ba237b11a1c6932a11aa440123422fe9ea49773c8ac.exe"
    1⤵
    • Writes to the Master Boot Record (MBR)
    • Modifies registry class
    • Suspicious use of FindShellTrayWindow
    • Suspicious use of SendNotifyMessage
    PID:3540

Network

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Local\Temp\install_res\installconfig.ini
    Filesize

    85B

    MD5

    417603898593dbd933edaff0706b3825

    SHA1

    2b1aec0f4d5d6831e90a9af3e8fa4b08fdb64aab

    SHA256

    ffff9a835c2b23185022a7c7cd7022d12dc4dae25e1bea758a5c3737cf1fa722

    SHA512

    fc17686ed27d953b622a6eb62d9345b2c0285998f904ffd8d4a6eef9b71f4a487baa8590da6c9d689bd987da04e15b4e98f463b486246f711f5ba62b56a10306

  • memory/3540-16-0x00000000009F0000-0x00000000009F1000-memory.dmp
    Filesize

    4KB

  • memory/3540-19-0x00000000009F0000-0x00000000009F1000-memory.dmp
    Filesize

    4KB