Analysis

  • max time kernel
    121s
  • max time network
    127s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 01:11

General

  • Target

    18fd0471029adc5a608cc7c442a97f3a.exe

  • Size

    355KB

  • MD5

    18fd0471029adc5a608cc7c442a97f3a

  • SHA1

    74854bda1aa3e60c3b6f58e8f77882ac7f958486

  • SHA256

    1e92e176dd94bb165b9ac9a391ed84ad473ae69a44139d2f9765dd56974cee0d

  • SHA512

    9cc462178cf8b63b27de90998c3a8cc722cec0bbde604e66482510c3888a78b1e869b4d3e7195c3361bb7fce43392c204c5b760948afd3bbddd6ee225bb61e00

  • SSDEEP

    6144:MM/FgKFH4ZtKyKtHFrO/ODMruf29AYlxJzZfPkcdeyO9U/PRdygA/g3/FGXIqNPo:MI/FutKyQli/3rtT5zPdeyO9U/PRdygE

Score
7/10

Malware Config

Signatures

  • Loads dropped DLL 1 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\18fd0471029adc5a608cc7c442a97f3a.exe
    "C:\Users\Admin\AppData\Local\Temp\18fd0471029adc5a608cc7c442a97f3a.exe"
    1⤵
    • Loads dropped DLL
    PID:2132

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • \Users\Admin\AppData\Roaming\d3d9.dll
    Filesize

    419KB

    MD5

    be83077acea269c2187e97bb1b69105d

    SHA1

    987759a7153784121f4ef96cf4d78d1e9c552fc3

    SHA256

    4045ce5f58a63dd9cf525424f950f8d6ea8be2d0b93069b691077480787ffa78

    SHA512

    e9f6da69af0730912586d4a8d388069872f1ed27e2e1b0c54570add6ded52f5e0e1da268e55615cd82076fa2fb1dd559cca7bda23e45fa2cc5c08e1cfa8c6e94

  • memory/2132-0-0x000000007448E000-0x000000007448F000-memory.dmp
    Filesize

    4KB

  • memory/2132-1-0x0000000001070000-0x00000000010D2000-memory.dmp
    Filesize

    392KB

  • memory/2132-2-0x0000000000450000-0x0000000000456000-memory.dmp
    Filesize

    24KB

  • memory/2132-7-0x0000000075300000-0x00000000753C1000-memory.dmp
    Filesize

    772KB

  • memory/2132-8-0x0000000074480000-0x0000000074B6E000-memory.dmp
    Filesize

    6.9MB