Analysis
-
max time kernel
121s -
max time network
123s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 01:58
Behavioral task
behavioral1
Sample
bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe
Resource
win7-20240221-en
1 signatures
150 seconds
Behavioral task
behavioral2
Sample
bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe
Resource
win10v2004-20240508-en
0 signatures
150 seconds
General
-
Target
bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe
-
Size
731KB
-
MD5
1903c93334e9cc6b2e34327b341dd990
-
SHA1
6c9bec2ecec1a5885843bdafd3ff20f775aed031
-
SHA256
bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5
-
SHA512
850069328fff220ed95070c7b79e50affd4ec5f0d367e6326b0af93623b66ae9ef04e9c01159404b8578c621ca52caf3ece9a9ada60a77921a15a9497ba9e43a
-
SSDEEP
6144:Fp19SmYRZbsuSBs3ojpe6aABlwZFsr5pOGJr3eRqk3tJc+xZRtiKzvzaOKIeM87e:Fp1EPZbsu2s3ojpe6aeSg3DeRqkUWp
Score
1/10
Malware Config
Signatures
-
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exedescription pid process target process PID 1692 wrote to memory of 1380 1692 bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe WerFault.exe PID 1692 wrote to memory of 1380 1692 bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe WerFault.exe PID 1692 wrote to memory of 1380 1692 bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe WerFault.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe"C:\Users\Admin\AppData\Local\Temp\bafb6234e9debea1df31c9ac741c820f03cc201753cc25c7b30005ff364896d5.exe"1⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\WerFault.exeC:\Windows\system32\WerFault.exe -u -p 1692 -s 762⤵