Analysis

  • max time kernel
    5s
  • max time network
    100s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:10

General

  • Target

    WinThruster/WinThruster.exe

  • Size

    10.3MB

  • MD5

    89b970cb172b86730c76c3df31551767

  • SHA1

    0ae55b3a41e4fc1c3074dbb738065ac4cd2309e5

  • SHA256

    7e97fe6c675e5842f38514056b2c3c7a928185f4dd2cdd97cd0d0ee4d5d319fd

  • SHA512

    18b0416e3120e1554845153f988a5757e3d03605e729450f93393611566cbc6f904b9acae6ffabafdef673c2d1b4b77fb688f27ab7437eec5428fb48aad246ba

  • SSDEEP

    98304:RDw3Ni9wMMTis0Vu2KKHGAmm3X+A3G8ZyUC3EQED2enKAcOe9z3eH4l40Mffh/b:G3Ni9zzFmmBgUUk9MOe9yObMXh/b

Score
7/10

Malware Config

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\WinThruster\WinThruster.exe
    "C:\Users\Admin\AppData\Local\Temp\WinThruster\WinThruster.exe"
    1⤵
    • Checks processor information in registry
    PID:3736
    • C:\Windows\SysWOW64\schtasks.exe
      "C:\Windows\System32\schtasks.exe" /Create /TN "WinThruster automatic scan and notifications" /TR "\"C:\Users\Admin\AppData\Local\Temp\WinThruster\WTNotifications.exe\"" /SC ONLOGON /RL HIGHEST /F
      2⤵
      • Scheduled Task/Job: Scheduled Task
      PID:4684
    • C:\Users\Admin\AppData\Local\Temp\WinThruster\WTNotifications.exe
      "C:\Users\Admin\AppData\Local\Temp\WinThruster\WTNotifications.exe"
      2⤵
        PID:4368

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Execution

    Scheduled Task/Job

    1
    T1053

    Scheduled Task

    1
    T1053.005

    Persistence

    Scheduled Task/Job

    1
    T1053

    Scheduled Task

    1
    T1053.005

    Privilege Escalation

    Scheduled Task/Job

    1
    T1053

    Scheduled Task

    1
    T1053.005

    Credential Access

    Unsecured Credentials

    1
    T1552

    Credentials In Files

    1
    T1552.001

    Discovery

    System Information Discovery

    2
    T1082

    Query Registry

    1
    T1012

    Collection

    Data from Local System

    1
    T1005

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\Users\Admin\AppData\Roaming\WinThruster\Log\Tasks.log
      Filesize

      416B

      MD5

      6b150ba809cce29c574d81de4d043369

      SHA1

      23f32083131d1db7aa40ed6db065991273e6df59

      SHA256

      1e2034fc4360e036448df635b9a30763d8423b5fc7cfa13a93c79fda347ca8f2

      SHA512

      b105c9c56345894e430dc5a5ee38d01795301a44dc0f35840810bccf77705cf0f701056520123bfe8803d11c8431ca990fda347db29d40eb85d8269808489dd1

    • memory/3736-0-0x0000000000CC0000-0x0000000000CC1000-memory.dmp
      Filesize

      4KB

    • memory/3736-31-0x0000000061E00000-0x0000000061EF4000-memory.dmp
      Filesize

      976KB

    • memory/3736-30-0x0000000000CE0000-0x000000000173E000-memory.dmp
      Filesize

      10.4MB

    • memory/3736-36-0x0000000000CC0000-0x0000000000CC1000-memory.dmp
      Filesize

      4KB

    • memory/4368-20-0x0000000000F50000-0x0000000000F51000-memory.dmp
      Filesize

      4KB

    • memory/4368-32-0x00000000002D0000-0x00000000007D1000-memory.dmp
      Filesize

      5.0MB

    • memory/4368-33-0x0000000061E00000-0x0000000061EF4000-memory.dmp
      Filesize

      976KB

    • memory/4368-39-0x0000000000F50000-0x0000000000F51000-memory.dmp
      Filesize

      4KB

    • memory/4368-54-0x00000000002D0000-0x00000000007D1000-memory.dmp
      Filesize

      5.0MB