Analysis

  • max time kernel
    147s
  • max time network
    133s
  • platform
    windows7_x64
  • resource
    win7-20240220-en
  • resource tags

    arch:x64arch:x86image:win7-20240220-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 05:25

General

  • Target

    VSeeFace/VSeeFace.exe

  • Size

    635KB

  • MD5

    9563b46fe7df442172a569f2c90f8231

  • SHA1

    a9cd7810d711e6e613f87608a47492fa1b100adb

  • SHA256

    0011d598ab64aab694d405dd280306adfcc8f2627e0af2252b0ec4dc8419bacc

  • SHA512

    ed62afbe9254f8e7b5b2f289077ac44e61ac768886da0693ad85b9fafff195c75e129bfbe27c23509b50878da8f7ad81654222e96f5a5e416d16acbb61c4b3d8

  • SSDEEP

    3072:Pys7oYfSbbQTLWuiUg7VsS4jMvN0AeUNEizWOFgyPIkL3ukqfuF:P/7oYfSHQPWTUg4ht+zWqgyVf

Score
1/10

Malware Config

Signatures

  • Modifies system certificate store 2 TTPs 2 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs
  • Suspicious use of WriteProcessMemory 3 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\VSeeFace\VSeeFace.exe
    "C:\Users\Admin\AppData\Local\Temp\VSeeFace\VSeeFace.exe"
    1⤵
    • Modifies system certificate store
    • Suspicious use of SetWindowsHookEx
    • Suspicious use of WriteProcessMemory
    PID:1780
    • C:\Users\Admin\AppData\Local\Temp\VSeeFace\UnityCrashHandler64.exe
      "C:\Users\Admin\AppData\Local\Temp\VSeeFace\UnityCrashHandler64.exe" --attach 1780 2101248
      2⤵
        PID:1796

    Network

    MITRE ATT&CK Matrix ATT&CK v13

    Defense Evasion

    Subvert Trust Controls

    1
    T1553

    Install Root Certificate

    1
    T1553.004

    Modify Registry

    1
    T1112

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      175B

      MD5

      abd113c3199d90dcfe9fea676c21ba5a

      SHA1

      48e45e2532e9e17ef438a4e43391a7a65ed453b8

      SHA256

      eeb89bde8456586db4ea345eb3b010fea5e1f41902a975f3b3f9b1df39e914d2

      SHA512

      427672ab5a5abc690019de5b357a21dfceb95285e794cbb766b2e5779e56f4f1ac3211b9befb44c43102db5e9cfa1bbd897caaebe186a273f66a7df26898a7b7

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      703B

      MD5

      6fd127f7842fb3a2bbcb887456e5bab5

      SHA1

      989e7e11ec295dd6344e9de7b8b5b5393e2543ec

      SHA256

      95d56880f61bd11e6656db1f3376779e504c447d0a8501d521771c9e830624d0

      SHA512

      cc1f46c584a07de7b3a208052d336860676f253021431a3fadd2720dd91f741c792be131434e2b56f2baf6eab39fae58edf299be884b81107c86196a7c855d2c

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      29B

      MD5

      7186ab3466d1fecbeaad7f0f075df97a

      SHA1

      f5552ff61b8fd2f4530848483f81fe5adec178fe

      SHA256

      37a93155ff507ea3328345ef224ff43fe770d2e26cd7eaa303b2e5c45dd54149

      SHA512

      75218b57ff10713e47de466824cc51716b08d4d720fd6f31dfdd3f9efd581502df315aa523948053f144f81be76735c6226dace4e3b3f8286b5e8fb45c7bb654

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      88B

      MD5

      68736a761281424eae15ef6022901f29

      SHA1

      80cfd67141aab9bd969ebbffd7dbdc8b4b8333c1

      SHA256

      6b9e7d195106d86cf7e5560c023e55faa6651f8a41e6f5ccb6389daa501b2638

      SHA512

      daabfd99bb9f0fc3bda79b95d73e476c89abd67202ea778f168eda83cbf7d5346e2245227e913f41c8cda9fadaf73386cd3f49f5597aa751dea30c1158f1cb09

    • C:\Users\Admin\AppData\LocalLow\Emiliana_vt\VSeeFace\settings.ini
      Filesize

      139B

      MD5

      56469a8d0666299020206ea9cd180f6d

      SHA1

      67c95995443b42bfea2b47a402e942c10e98f9bb

      SHA256

      29eb89002600ce6d0ffee7fc7dcbecf4e88938dc3eecf37c9c2a61e94a1240dc

      SHA512

      930323fedd03d946e09086c4f1343f589556c0aad07b42098a15ed9831ddb4ae23838a4b1df878b3af113df0c92c9ce6880789fd82de118e33221444979c4cf9

    • memory/1780-92-0x00000000633D0000-0x00000000633E0000-memory.dmp
      Filesize

      64KB

    • memory/1780-15-0x0000000062E50000-0x0000000062E60000-memory.dmp
      Filesize

      64KB

    • memory/1780-2-0x0000000002140000-0x0000000002150000-memory.dmp
      Filesize

      64KB

    • memory/1780-3-0x0000000002150000-0x0000000002160000-memory.dmp
      Filesize

      64KB

    • memory/1780-12-0x0000000062E40000-0x0000000062E50000-memory.dmp
      Filesize

      64KB

    • memory/1780-195-0x0000000064190000-0x00000000641A0000-memory.dmp
      Filesize

      64KB

    • memory/1780-18-0x0000000062FC0000-0x0000000062FD0000-memory.dmp
      Filesize

      64KB

    • memory/1780-19-0x0000000062FD0000-0x0000000062FE0000-memory.dmp
      Filesize

      64KB

    • memory/1780-20-0x0000000063170000-0x0000000063180000-memory.dmp
      Filesize

      64KB

    • memory/1780-21-0x000007FFFFEB0000-0x000007FFFFEC0000-memory.dmp
      Filesize

      64KB

    • memory/1780-198-0x00000000639E0000-0x00000000639F0000-memory.dmp
      Filesize

      64KB

    • memory/1780-28-0x0000000000230000-0x0000000000240000-memory.dmp
      Filesize

      64KB

    • memory/1780-27-0x0000000000240000-0x0000000000250000-memory.dmp
      Filesize

      64KB

    • memory/1780-31-0x00000000633C0000-0x00000000633D0000-memory.dmp
      Filesize

      64KB

    • memory/1780-30-0x0000000002140000-0x0000000002150000-memory.dmp
      Filesize

      64KB

    • memory/1780-33-0x00000000633D0000-0x00000000633E0000-memory.dmp
      Filesize

      64KB

    • memory/1780-32-0x0000000002150000-0x0000000002160000-memory.dmp
      Filesize

      64KB

    • memory/1780-34-0x0000000062E40000-0x0000000062E50000-memory.dmp
      Filesize

      64KB

    • memory/1780-36-0x00000000637A0000-0x00000000637B0000-memory.dmp
      Filesize

      64KB

    • memory/1780-35-0x0000000062E50000-0x0000000062E60000-memory.dmp
      Filesize

      64KB

    • memory/1780-37-0x0000000062FC0000-0x0000000062FD0000-memory.dmp
      Filesize

      64KB

    • memory/1780-38-0x0000000062FD0000-0x0000000062FE0000-memory.dmp
      Filesize

      64KB

    • memory/1780-39-0x00000000639E0000-0x00000000639F0000-memory.dmp
      Filesize

      64KB

    • memory/1780-40-0x0000000063170000-0x0000000063180000-memory.dmp
      Filesize

      64KB

    • memory/1780-41-0x0000000063A80000-0x0000000063AA0000-memory.dmp
      Filesize

      128KB

    • memory/1780-42-0x00000000639F0000-0x0000000063A00000-memory.dmp
      Filesize

      64KB

    • memory/1780-62-0x0000000063C80000-0x0000000063C90000-memory.dmp
      Filesize

      64KB

    • memory/1780-64-0x0000000063C90000-0x0000000063CA0000-memory.dmp
      Filesize

      64KB

    • memory/1780-63-0x00000000632B0000-0x00000000632C0000-memory.dmp
      Filesize

      64KB

    • memory/1780-162-0x00000000637A0000-0x00000000637B0000-memory.dmp
      Filesize

      64KB

    • memory/1780-94-0x0000000063FB0000-0x0000000063FC0000-memory.dmp
      Filesize

      64KB

    • memory/1780-1-0x0000000000230000-0x0000000000240000-memory.dmp
      Filesize

      64KB

    • memory/1780-102-0x0000000063FC0000-0x0000000063FD0000-memory.dmp
      Filesize

      64KB

    • memory/1780-163-0x0000000063FD0000-0x0000000063FE0000-memory.dmp
      Filesize

      64KB

    • memory/1780-87-0x00000000633C0000-0x00000000633D0000-memory.dmp
      Filesize

      64KB

    • memory/1780-0-0x0000000000240000-0x0000000000250000-memory.dmp
      Filesize

      64KB

    • memory/1780-29-0x00000000632B0000-0x00000000632C0000-memory.dmp
      Filesize

      64KB

    • memory/1780-199-0x00000000642C0000-0x00000000642D0000-memory.dmp
      Filesize

      64KB

    • memory/1780-200-0x0000000063A80000-0x0000000063AA0000-memory.dmp
      Filesize

      128KB

    • memory/1780-201-0x0000000064330000-0x0000000064340000-memory.dmp
      Filesize

      64KB

    • memory/1780-202-0x00000000639F0000-0x0000000063A00000-memory.dmp
      Filesize

      64KB

    • memory/1780-203-0x0000000064340000-0x0000000064350000-memory.dmp
      Filesize

      64KB

    • memory/1780-204-0x0000000063C80000-0x0000000063C90000-memory.dmp
      Filesize

      64KB

    • memory/1780-205-0x0000000064350000-0x0000000064360000-memory.dmp
      Filesize

      64KB

    • memory/1780-206-0x0000000063C90000-0x0000000063CA0000-memory.dmp
      Filesize

      64KB

    • memory/1780-207-0x0000000064360000-0x0000000064380000-memory.dmp
      Filesize

      128KB

    • memory/1780-208-0x0000000064480000-0x0000000064490000-memory.dmp
      Filesize

      64KB

    • memory/1780-209-0x000007FFFFEC0000-0x000007FFFFED0000-memory.dmp
      Filesize

      64KB

    • memory/1780-219-0x0000000063FB0000-0x0000000063FC0000-memory.dmp
      Filesize

      64KB

    • memory/1780-220-0x00000000646E0000-0x00000000646F0000-memory.dmp
      Filesize

      64KB

    • memory/1780-221-0x0000000063FC0000-0x0000000063FD0000-memory.dmp
      Filesize

      64KB

    • memory/1780-222-0x00000000646F0000-0x0000000064700000-memory.dmp
      Filesize

      64KB

    • memory/1780-234-0x000007FFFFE70000-0x000007FFFFE80000-memory.dmp
      Filesize

      64KB

    • memory/1780-273-0x000007FFFFE00000-0x000007FFFFE10000-memory.dmp
      Filesize

      64KB

    • memory/1780-274-0x000007FFFFE00000-0x000007FFFFE10000-memory.dmp
      Filesize

      64KB

    • memory/1780-277-0x000007FFFFE10000-0x000007FFFFE20000-memory.dmp
      Filesize

      64KB

    • memory/1780-295-0x000007FFFFDD0000-0x000007FFFFDE0000-memory.dmp
      Filesize

      64KB

    • memory/1780-297-0x0000000063FD0000-0x0000000063FE0000-memory.dmp
      Filesize

      64KB

    • memory/1780-298-0x0000000065A60000-0x0000000065A70000-memory.dmp
      Filesize

      64KB

    • memory/1780-307-0x000007FFFFDB0000-0x000007FFFFDD0000-memory.dmp
      Filesize

      128KB

    • memory/1780-336-0x0000000064190000-0x00000000641A0000-memory.dmp
      Filesize

      64KB

    • memory/1780-337-0x00000000642C0000-0x00000000642D0000-memory.dmp
      Filesize

      64KB

    • memory/1780-338-0x0000000064330000-0x0000000064340000-memory.dmp
      Filesize

      64KB

    • memory/1780-339-0x0000000064340000-0x0000000064350000-memory.dmp
      Filesize

      64KB

    • memory/1780-340-0x0000000064350000-0x0000000064360000-memory.dmp
      Filesize

      64KB

    • memory/1780-341-0x0000000064360000-0x0000000064380000-memory.dmp
      Filesize

      128KB

    • memory/1780-342-0x0000000064480000-0x0000000064490000-memory.dmp
      Filesize

      64KB

    • memory/1780-343-0x00000000646E0000-0x00000000646F0000-memory.dmp
      Filesize

      64KB

    • memory/1780-344-0x00000000646F0000-0x0000000064700000-memory.dmp
      Filesize

      64KB

    • memory/1780-345-0x0000000065A60000-0x0000000065A70000-memory.dmp
      Filesize

      64KB