Analysis

  • max time kernel
    148s
  • max time network
    159s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 05:25

General

  • Target

    VSeeFace/VSeeFace.exe

  • Size

    635KB

  • MD5

    9563b46fe7df442172a569f2c90f8231

  • SHA1

    a9cd7810d711e6e613f87608a47492fa1b100adb

  • SHA256

    0011d598ab64aab694d405dd280306adfcc8f2627e0af2252b0ec4dc8419bacc

  • SHA512

    ed62afbe9254f8e7b5b2f289077ac44e61ac768886da0693ad85b9fafff195c75e129bfbe27c23509b50878da8f7ad81654222e96f5a5e416d16acbb61c4b3d8

  • SSDEEP

    3072:Pys7oYfSbbQTLWuiUg7VsS4jMvN0AeUNEizWOFgyPIkL3ukqfuF:P/7oYfSHQPWTUg4ht+zWqgyVf

Score
1/10

Malware Config

Signatures

  • Modifies system certificate store 2 TTPs 3 IoCs
  • Suspicious use of AdjustPrivilegeToken 2 IoCs
  • Suspicious use of SetWindowsHookEx 1 IoCs
  • Suspicious use of WriteProcessMemory 2 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\VSeeFace\VSeeFace.exe
    "C:\Users\Admin\AppData\Local\Temp\VSeeFace\VSeeFace.exe"
    1⤵
    • Modifies system certificate store
    • Suspicious use of SetWindowsHookEx
    • Suspicious use of WriteProcessMemory
    PID:3360
    • C:\Users\Admin\AppData\Local\Temp\VSeeFace\UnityCrashHandler64.exe
      "C:\Users\Admin\AppData\Local\Temp\VSeeFace\UnityCrashHandler64.exe" --attach 3360 2164143165440
      2⤵
        PID:4904
    • C:\Windows\system32\AUDIODG.EXE
      C:\Windows\system32\AUDIODG.EXE 0x150 0x530
      1⤵
      • Suspicious use of AdjustPrivilegeToken
      PID:3028

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Defense Evasion

    Subvert Trust Controls

    1
    T1553

    Install Root Certificate

    1
    T1553.004

    Modify Registry

    1
    T1112

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      175B

      MD5

      abd113c3199d90dcfe9fea676c21ba5a

      SHA1

      48e45e2532e9e17ef438a4e43391a7a65ed453b8

      SHA256

      eeb89bde8456586db4ea345eb3b010fea5e1f41902a975f3b3f9b1df39e914d2

      SHA512

      427672ab5a5abc690019de5b357a21dfceb95285e794cbb766b2e5779e56f4f1ac3211b9befb44c43102db5e9cfa1bbd897caaebe186a273f66a7df26898a7b7

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      703B

      MD5

      6fd127f7842fb3a2bbcb887456e5bab5

      SHA1

      989e7e11ec295dd6344e9de7b8b5b5393e2543ec

      SHA256

      95d56880f61bd11e6656db1f3376779e504c447d0a8501d521771c9e830624d0

      SHA512

      cc1f46c584a07de7b3a208052d336860676f253021431a3fadd2720dd91f741c792be131434e2b56f2baf6eab39fae58edf299be884b81107c86196a7c855d2c

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      139B

      MD5

      56469a8d0666299020206ea9cd180f6d

      SHA1

      67c95995443b42bfea2b47a402e942c10e98f9bb

      SHA256

      29eb89002600ce6d0ffee7fc7dcbecf4e88938dc3eecf37c9c2a61e94a1240dc

      SHA512

      930323fedd03d946e09086c4f1343f589556c0aad07b42098a15ed9831ddb4ae23838a4b1df878b3af113df0c92c9ce6880789fd82de118e33221444979c4cf9

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      29B

      MD5

      7186ab3466d1fecbeaad7f0f075df97a

      SHA1

      f5552ff61b8fd2f4530848483f81fe5adec178fe

      SHA256

      37a93155ff507ea3328345ef224ff43fe770d2e26cd7eaa303b2e5c45dd54149

      SHA512

      75218b57ff10713e47de466824cc51716b08d4d720fd6f31dfdd3f9efd581502df315aa523948053f144f81be76735c6226dace4e3b3f8286b5e8fb45c7bb654

    • memory/3360-1-0x000001F7E28D0000-0x000001F7E28E0000-memory.dmp
      Filesize

      64KB

    • memory/3360-0-0x000001F7E2B90000-0x000001F7E2BA0000-memory.dmp
      Filesize

      64KB

    • memory/3360-169-0x000001F7E28D0000-0x000001F7E28E0000-memory.dmp
      Filesize

      64KB

    • memory/3360-168-0x000001F7E2B90000-0x000001F7E2BA0000-memory.dmp
      Filesize

      64KB