Analysis
-
max time kernel
145s -
max time network
118s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 04:30
Static task
static1
Behavioral task
behavioral1
Sample
f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe
Resource
win7-20240508-en
General
-
Target
f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe
-
Size
439KB
-
MD5
baf0258af5ebcb9b1e20547193c99417
-
SHA1
f4f6ec34a68af717964e1cc5fa5abf4d12341b7d
-
SHA256
f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878
-
SHA512
1a5a2b1cdf28aca540cc21a2d7964df8ca5930cf342104d8c6466033d0ab6511c8966cc4c02251b9e913190ef0756ed99d019f6536131674f9cf151c0cc63160
-
SSDEEP
12288:s3C9JvaIScAcySTDzeTWwSaKsuflz+cVWKtwAtsP/AZ9:oC9ktQTPeTWVRjLtwAeP/W
Malware Config
Signatures
-
Executes dropped EXE 1 IoCs
Processes:
26E2.tmppid process 1860 26E2.tmp -
Loads dropped DLL 2 IoCs
Processes:
f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exepid process 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe -
Reads user/profile data of web browsers 2 TTPs
Infostealers often target stored browser data, which can include saved credentials etc.
-
Drops file in System32 directory 64 IoCs
Processes:
26E2.tmpdescription ioc process File created C:\Windows\SysWOW64\olecli32.dll 26E2.tmp File created C:\Windows\SysWOW64\ir41_32.ax 26E2.tmp File created C:\Windows\SysWOW64\ir50_32.dll 26E2.tmp File created C:\Windows\SysWOW64\ivfsrc.ax 26E2.tmp File opened for modification C:\Windows\SysWOW64\msvcr100.dll 26E2.tmp File created C:\Windows\SysWOW64\msxbde40.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\VBAME.DLL 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_amd64_neutral_54a12b57f547d08e\igdumd32.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc110u.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc120.dll 26E2.tmp File created C:\Windows\SysWOW64\msexcl40.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\msvcr120_clr0400.dll 26E2.tmp File created C:\Windows\SysWOW64\mswdat10.dll 26E2.tmp File created C:\Windows\SysWOW64\InstallShield\setup.exe 26E2.tmp File created C:\Windows\SysWOW64\migration\MediaPlayer-DLMigPlugin.dll 26E2.tmp File created C:\Windows\SysWOW64\d3d8.dll 26E2.tmp File created C:\Windows\SysWOW64\dplayx.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc140.dll 26E2.tmp File created C:\Windows\SysWOW64\msvcrt20.dll 26E2.tmp File created C:\Windows\SysWOW64\msltus40.dll 26E2.tmp File created C:\Windows\SysWOW64\sqlunirl.dll 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atidxx32.dll 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\nv_lh.inf_amd64_neutral_bc69f20e3115af59\nvd3dum.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\atl110.dll 26E2.tmp File created C:\Windows\SysWOW64\dplaysvr.exe 26E2.tmp File created C:\Windows\SysWOW64\odbcjt32.dll 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\amdpcom32.dll 26E2.tmp File created C:\Windows\SysWOW64\sqlwoa.dll 26E2.tmp File created C:\Windows\SysWOW64\d3dim.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc120u.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\MSCOMCTL.OCX 26E2.tmp File created C:\Windows\SysWOW64\mstext40.dll 26E2.tmp File created C:\Windows\SysWOW64\msjtes40.dll 26E2.tmp File created C:\Windows\SysWOW64\regedit.exe 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc140u.dll 26E2.tmp File created C:\Windows\SysWOW64\mfc40.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\msvcr110.dll 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\igdlh.inf_amd64_neutral_54a12b57f547d08e\igd10umd32.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\atl100.dll 26E2.tmp File created C:\Windows\SysWOW64\d3dxof.dll 26E2.tmp File created C:\Windows\SysWOW64\explorer.exe 26E2.tmp File opened for modification C:\Windows\SysWOW64\FM20.DLL 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\nv_lh.inf_amd64_neutral_bc69f20e3115af59\nvwgf2um.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\concrt140.dll 26E2.tmp File created C:\Windows\SysWOW64\dpwsockx.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc110.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\msvcr120.dll 26E2.tmp File created C:\Windows\SysWOW64\setupSNK.exe 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumdag.dll 26E2.tmp File created C:\Windows\SysWOW64\audiodev.dll 26E2.tmp File created C:\Windows\SysWOW64\dmscript.dll 26E2.tmp File created C:\Windows\SysWOW64\iac25_32.ax 26E2.tmp File created C:\Windows\SysWOW64\msrd3x40.dll 26E2.tmp File created C:\Windows\SysWOW64\msrepl40.dll 26E2.tmp File created C:\Windows\SysWOW64\migwiz\dlmanifests\Microsoft-Windows-MediaPlayer\MediaPlayer-DLMigPlugin.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\mfc100u.dll 26E2.tmp File created C:\Windows\SysWOW64\msjet40.dll 26E2.tmp File created C:\Windows\SysWOW64\msorcl32.dll 26E2.tmp File created C:\Windows\SysWOW64\msrd2x40.dll 26E2.tmp File created C:\Windows\System32\DriverStore\FileRepository\atiilhag.inf_amd64_neutral_0a660e899f5038a2\atiumdva.dll 26E2.tmp File created C:\Windows\SysWOW64\d3dim700.dll 26E2.tmp File created C:\Windows\SysWOW64\mswstr10.dll 26E2.tmp File created C:\Windows\SysWOW64\rdvgumd32.dll 26E2.tmp File opened for modification C:\Windows\SysWOW64\vccorlib120.dll 26E2.tmp -
Drops file in Program Files directory 64 IoCs
Processes:
26E2.tmpdescription ioc process File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\MAPIPH.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\MAPISHELL.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\MSODCW.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\SCNPST64.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\WebKit.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\GRAPH.EXE 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\MSOSV.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OART.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\VPREVIEW.EXE 26E2.tmp File opened for modification C:\Program Files\7-Zip\7zCon.sfx 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\RICHED20.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\CONVERT\OLJRNL.FAE 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\BIBUtils.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\MSACCESS.EXE 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\EntityPicker.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEMANAGED.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Multimedia.api 26E2.tmp File opened for modification C:\Program Files (x86)\Google\Update\1.3.36.151\GoogleCrashHandler.exe 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\oisctrl.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\TaxonomyControl.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\PROOF\MSHY7FR.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Esl\AiodLite.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\System\Ole DB\xmlrwbin.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WPFT532.CNV 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Web Server Extensions\14\BIN\FPWEC.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\MSYUBIN7.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\FBIBLIO.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\FDATE.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OUTLFLTR.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Multimedia\MPP\QuickTime.mpp 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OMSMAIN.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\PROOF\MSHY7EN.DLL 26E2.tmp File created C:\Program Files (x86)\Adobe\Reader 9.0\Reader\LogTransport2.exe 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Analysis Services\AS OLEDB\10\msmgdsrv.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\mset7tkjp.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OneNoteSyncPC.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OUTLPH.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\MOFL.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\TRANSLAT\ESEN\MSB1ESEN.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Multimedia\MPP\Real.mpp 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSO.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\VVIEWER.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\PROOF\1036\MSGR3FR.DLL 26E2.tmp File opened for modification C:\Program Files\7-Zip\7z.sfx 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\plug_ins\Multimedia\MPP\MCIMPP.mpp 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\USP10.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WksConv\Wkconv.exe 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\ACCDDS.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\GKWord.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Sync Framework\v1.0\Runtime\x86\Synchronization.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\EQUATION\EQNEDT32.EXE 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\ACEEXCL.DLL 26E2.tmp File created C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\FPLACE.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\STSLIST.DLL 26E2.tmp File created C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AXE8SharedExpat.dll 26E2.tmp File opened for modification C:\Program Files (x86)\Adobe\Reader 9.0\Reader\SPPlugins\ADMPlugin.apl 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\EXSEC32.DLL 26E2.tmp File opened for modification C:\Program Files (x86)\Microsoft Office\Office14\OIS.EXE 26E2.tmp File created C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AdobeLinguistic.dll 26E2.tmp -
Drops file in Windows directory 64 IoCs
Processes:
26E2.tmpdescription ioc process File opened for modification C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsecimpl.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_1eaaa4a07717236e\wininet.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ie-ielowutil_31bf3856ad364e35_11.2.9600.16428_none_8cae83b0cdeb7a9b\ielowutil.exe 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-msxml30_31bf3856ad364e35_6.1.7601.17514_none_f0e8f05be1d66e78\msxml3.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-fontview_31bf3856ad364e35_6.1.7600.16385_none_443a636317ca9b75\fontview.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ie-iexpress_31bf3856ad364e35_8.0.7600.16385_none_7f0c7a3c17077fce\iexpress.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\NlbMigPlugin.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-s..configurationengine_31bf3856ad364e35_6.1.7601.17514_none_bb2c4d9ee6dcc35c\scesrv.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\esscli.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-directshow-core_31bf3856ad364e35_6.1.7601.17514_none_0eeae7a238e677c8\quartz.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-remoteassistance-exe_31bf3856ad364e35_6.1.7600.16385_none_9da1b3254ff796e9\sdchange.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-directx-direct3d10_31bf3856ad364e35_6.1.7600.16385_none_ef8ebbc22eff9332\d3d10.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-g..licy-admin-scrptadm_31bf3856ad364e35_6.1.7601.17514_none_d370f9aac313993d\scrptadm.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.7601.17514_none_644ee1186f7d145b\IEShims.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.1.7601.17514_none_04801f69e1dbd8e6\ndismigplugin.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-wmcodecdspps_31bf3856ad364e35_6.1.7600.16385_none_e344e0de5741a951\wmcodecdspps.dll 26E2.tmp File created C:\Windows\winsxs\Backup\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4a5d2c9ecd59afa7_dnscacheugc.exe_aa32623e 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-d..s-ime-japanese-core_31bf3856ad364e35_6.1.7600.16385_none_d5b4f96cdbb9a8b1\IMJPMGR.EXE 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-mediaplayer-drm_31bf3856ad364e35_6.1.7601.17514_none_d6a8cb040fcd3a85\drmmgrtn.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-mlang_31bf3856ad364e35_6.1.7600.16385_none_bd28e772321016e1\mlang.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-indeo4-codecs_31bf3856ad364e35_6.1.7600.16385_none_3ba474acb8a82ef6\ir41_32.ax 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-m..c-drivermanager-dll_31bf3856ad364e35_6.1.7601.17514_none_123a1c25483b3cd9\odbc32.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.1.7601.17514_none_373ecc0d14680e72\ehui.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-t..framework-migration_31bf3856ad364e35_6.1.7600.16385_none_f0c791fc196de3b5\msctfmig.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-taskkill_31bf3856ad364e35_6.1.7600.16385_none_25545528bd642170\taskkill.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-help-oemhelpins_31bf3856ad364e35_6.1.7600.16385_none_02251b880c000edf\OEMHelpIns.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ie-htmlconverter_31bf3856ad364e35_8.0.7601.17514_none_87da61075c9f17a8\html.iec 26E2.tmp File created C:\Windows\winsxs\Backup\x86_microsoft-windows-bcrypt-primitives-dll_31bf3856ad364e35_6.1.7600.16385_none_1207cf88785de24d_bcryptprimitives.dll_5dcb347c 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-mfc40_31bf3856ad364e35_6.1.7601.17514_none_5c06580240091047\mfc40.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-t..platform-comruntime_31bf3856ad364e35_6.1.7600.16385_none_ca66ddfc9862f744\rtscom.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-winrsplugins_31bf3856ad364e35_6.1.7600.16385_none_160ccc8a92fae520\winrs.exe 26E2.tmp File created C:\Windows\winsxs\Temp\PendingDeletes\$$DeleteMe.wininet.dll.01daa15371b80dc0.000a 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-iis-legacysnapin_31bf3856ad364e35_6.1.7601.17514_none_e99b83c8fd064a06\uihelper.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-mediafoundation_31bf3856ad364e35_6.1.7601.17514_none_04d9defd57c1f6bf\mfps.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.1.7601.17514_none_dd3eb6aced2f8d13\credui.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-time-tool_31bf3856ad364e35_6.1.7601.17514_none_ef1085419a309311\w32tm.exe 26E2.tmp File created C:\Windows\winsxs\x86_netfx-peverify_dll_b03f5f7f11d50a3a_6.1.7600.16385_none_711dc6fb06230c92\peverify.dll 26E2.tmp File created C:\Windows\Installer\$PatchCache$\Managed\1D5E3C0FEDA1E123187686FED06E995A\10.0.40219\F_CENTRAL_mfc100_x86 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-c..plus-admin-comadmin_31bf3856ad364e35_6.1.7600.16385_none_313785582054d3f3\comadmin.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-d..ime-eashared-imepad_31bf3856ad364e35_6.1.7601.17514_none_3c93ac15fd731acf\IMEPADSV.EXE 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-difxapi_31bf3856ad364e35_6.1.7600.16385_none_0819f3b1f785b1ce\difxapi.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-msdt_31bf3856ad364e35_6.1.7600.16385_none_0bcbfdec6b984220\msdt.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-n.._service_runtimeapi_31bf3856ad364e35_6.1.7600.16385_none_8b6b5562c22f4547\iashlpr.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_11.2.9600.16428_none_1c0dbd69636d746a\ieUnatt.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-directx-direct3dxof_31bf3856ad364e35_6.1.7600.16385_none_af4b5c30460b0358\d3dxof.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.7601.17514_none_190fa02cb006154d\msfeedssync.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-n..n_service_migplugin_31bf3856ad364e35_6.1.7600.16385_none_5e24e56caba0b429\IasMigPlugin.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-osk_31bf3856ad364e35_6.1.7600.16385_none_aa93298fbb4246f2\osk.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-ribbons_31bf3856ad364e35_6.1.7601.17514_none_8abc4ded863e0452\Ribbons.scr 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-syncinfrastructure_31bf3856ad364e35_6.1.7600.16385_none_f838d0115142247e\SyncInfrastructure.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-deltacompressionengine_31bf3856ad364e35_6.1.7600.16385_none_4002be3be712af33\mspatcha.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-m..onents-jetexchlotus_31bf3856ad364e35_6.1.7600.16385_none_c3120b63aec6aa01\msltus40.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-m..ss-components-jetes_31bf3856ad364e35_6.1.7600.16385_none_36886cdd2e3bf7e4\msjtes40.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-icm-dccw_31bf3856ad364e35_6.1.7600.16385_none_813847d9dc951659\dccw.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-dssec_31bf3856ad364e35_6.1.7600.16385_none_5a3c2da65ddb680f\dssec.dll 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-msmpeg2enc_31bf3856ad364e35_6.1.7601.17514_none_0b450351a4424f06\MSMPEG2ENC.DLL 26E2.tmp File created C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-mediaplayer-drm_31bf3856ad364e35_6.1.7601.17514_none_d6a8cb040fcd3a85\drmv2clt.dll 26E2.tmp File created C:\Windows\winsxs\wow64_windowssearchengine_31bf3856ad364e35_7.0.7601.17514_none_dbd4d2796675bc72\SearchFilterHost.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-diantz_31bf3856ad364e35_6.1.7600.16385_none_a69c6a8f23f521f3\diantz.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-migration_31bf3856ad364e35_6.1.7601.17514_none_e02729035a3379c1\MediaPlayer-DLMigPlugin.dll 26E2.tmp File created C:\Windows\winsxs\wow64_microsoft-windows-ie-htmlapplication_31bf3856ad364e35_11.2.9600.16428_none_4605aca152cc8281\mshta.exe 26E2.tmp File created C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.1.7601.17514_none_affb336d34ccf2f8\setup_wm.exe 26E2.tmp File opened for modification C:\Windows\Microsoft.NET\Framework\v4.0.30319\AdoNetDiag.dll 26E2.tmp -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exedescription pid process target process PID 1636 wrote to memory of 1860 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe 26E2.tmp PID 1636 wrote to memory of 1860 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe 26E2.tmp PID 1636 wrote to memory of 1860 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe 26E2.tmp PID 1636 wrote to memory of 1860 1636 f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe 26E2.tmp
Processes
-
C:\Users\Admin\AppData\Local\Temp\f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe"C:\Users\Admin\AppData\Local\Temp\f132a5c70287246b6a99ad3c5a0f57a0ec42e1a14078f2d24212e97bedcf6878.exe"1⤵
- Loads dropped DLL
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\26E2.tmpC:\Users\Admin\AppData\Local\Temp\26E2.tmp2⤵
- Executes dropped EXE
- Drops file in System32 directory
- Drops file in Program Files directory
- Drops file in Windows directory
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\26E2.tmpFilesize
145KB
MD5c610e7ccd6859872c585b2a85d7dc992
SHA1362b3d4b72e3add687c209c79b500b7c6a246d46
SHA25614063fc61dc71b9881d75e93a587c27a6daf8779ff5255a24a042beace541041
SHA5128570aad2ae8b5dcba00fc5ebf3dc0ea117e96cc88a83febd820c5811bf617a6431c1367b3eb88332f43f80b30ebe2c298c22dcc44860a075f7b41bf350236666
-
memory/1636-0-0x0000000000230000-0x0000000000270000-memory.dmpFilesize
256KB