Overview
overview
10Static
static
3__x64___se...nv.dll
windows10-2004-x64
1__x64___se...or.dll
windows10-2004-x64
1__x64___se...vc.dll
windows10-2004-x64
1__x64___se...df.dll
windows10-2004-x64
1__x64___se...nc.dll
windows10-2004-x64
1__x64___se...tr.dll
windows10-2004-x64
1__x64___se...el.dll
windows10-2004-x64
1__x64___se...lg.dll
windows10-2004-x64
1__x64___se...ab.dll
windows10-2004-x64
1__x64___se...rf.dll
windows10-2004-x64
1__x64___se...on.dll
windows10-2004-x64
1__x64___se...al.dll
windows10-2004-x64
1__x64___se...SM.dll
windows10-2004-x64
1__x64___se...ms.dll
windows10-2004-x64
1__x64___se...20.dll
windows7-x64
1__x64___se...20.dll
windows10-2004-x64
1__x64___se...un.dll
windows10-2004-x64
7__x64___se...up.msi
windows7-x64
6__x64___se...up.msi
windows10-2004-x64
10__x64___se...ph.dll
windows10-2004-x64
1__x64___se...rs.dll
windows10-2004-x64
1__x64___se...rv.dll
windows10-2004-x64
1__x64___se...re.dll
windows10-2004-x64
1Analysis
-
max time kernel
122s -
max time network
124s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 04:18
Static task
static1
Behavioral task
behavioral1
Sample
__x64___setup___x32__/SettingMonitor/SessEnv.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral2
Sample
__x64___setup___x32__/SettingMonitor/SettingMonitor.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
__x64___setup___x32__/SettingMonitor/pnrpsvc.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral4
Sample
__x64___setup___x32__/SettingMonitor/uudf.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
__x64___setup___x32__/SettingSync/SettingSync.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral6
Sample
__x64___setup___x32__/SettingSync/rasmontr.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral7
Sample
__x64___setup___x32__/SettingSync/schannel.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral8
Sample
__x64___setup___x32__/SettingSync/sppcommdlg.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
__x64___setup___x32__/dab/dab.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral10
Sample
__x64___setup___x32__/dab/diagperf.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral11
Sample
__x64___setup___x32__/dab/fcon.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral12
Sample
__x64___setup___x32__/dab/hal.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
__x64___setup___x32__/mscms/NPSM.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral14
Sample
__x64___setup___x32__/mscms/mscms.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
__x64___setup___x32__/mscms/msvcp120.dll
Resource
win7-20240221-en
Behavioral task
behavioral16
Sample
__x64___setup___x32__/mscms/msvcp120.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
__x64___setup___x32__/mscms/scrrun.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral18
Sample
__x64___setup___x32__/setup.msi
Resource
win7-20240508-en
Behavioral task
behavioral19
Sample
__x64___setup___x32__/setup.msi
Resource
win10v2004-20240611-en
Behavioral task
behavioral20
Sample
__x64___setup___x32__/vmrdvcore/mssph.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
__x64___setup___x32__/vmrdvcore/perfctrs.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral22
Sample
__x64___setup___x32__/vmrdvcore/tapisrv.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral23
Sample
__x64___setup___x32__/vmrdvcore/vmrdvcore.dll
Resource
win10v2004-20240508-en
General
-
Target
__x64___setup___x32__/mscms/msvcp120.dll
-
Size
644KB
-
MD5
c2028ba6c66363b36ea659ca8816265d
-
SHA1
5e2bda10ad417466290dc08fd6ee8bc5fcf0ebbd
-
SHA256
3b92e964404e3f94531e7d7c4c7419561d9eca6accd98dc3979c9e3596db444c
-
SHA512
28e87d7360c4bd2eb30152173da6fdf30340b5ff0186a68f26514088dcc15758851afd01a179e976a91a9a85f9c1ee0cfa40308ed9d42654739acf6f6dd773f4
-
SSDEEP
12288:FOB4p+q4N8d4l2ms4cTHN+m+gy/vEPYysExtvsIvXi1ZG2EKZm+GWodEEpvY/p:iAtvsIvL2EKZm+GWodEEpvYh
Malware Config
Signatures
-
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
rundll32.exedescription pid process target process PID 2112 wrote to memory of 1932 2112 rundll32.exe WerFault.exe PID 2112 wrote to memory of 1932 2112 rundll32.exe WerFault.exe PID 2112 wrote to memory of 1932 2112 rundll32.exe WerFault.exe