Overview
overview
8Static
static
3_igetintop...re.url
windows7-x64
1_igetintop...re.url
windows10-2004-x64
1_igetintop...lp.url
windows7-x64
6_igetintop...lp.url
windows10-2004-x64
3_igetintop...12.exe
windows7-x64
8_igetintop...12.exe
windows10-2004-x64
7_igetintop...ch.exe
windows7-x64
8_igetintop...ch.exe
windows10-2004-x64
8Patch.exe
windows7-x64
8Patch.exe
windows10-2004-x64
8Analysis
-
max time kernel
148s -
max time network
150s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 05:43
Static task
static1
Behavioral task
behavioral1
Sample
_igetintopc.com_Internet_Download_Manager_6/Download Free Software.url
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
_igetintopc.com_Internet_Download_Manager_6/Download Free Software.url
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
_igetintopc.com_Internet_Download_Manager_6/Help.url
Resource
win7-20240220-en
Behavioral task
behavioral4
Sample
_igetintopc.com_Internet_Download_Manager_6/Help.url
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
_igetintopc.com_Internet_Download_Manager_6/idman642build12.exe
Resource
win7-20240221-en
Behavioral task
behavioral6
Sample
_igetintopc.com_Internet_Download_Manager_6/idman642build12.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
_igetintopc.com_Internet_Download_Manager_6/igetintopc.com_fix/Patch.exe
Resource
win7-20240611-en
Behavioral task
behavioral8
Sample
_igetintopc.com_Internet_Download_Manager_6/igetintopc.com_fix/Patch.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
Patch.exe
Resource
win7-20240611-en
Behavioral task
behavioral10
Sample
Patch.exe
Resource
win10v2004-20240508-en
General
-
Target
_igetintopc.com_Internet_Download_Manager_6/igetintopc.com_fix/Patch.exe
-
Size
59KB
-
MD5
27016937b5781c4f84b6b3432170f4d0
-
SHA1
bc812a8c4d44a3503ffd6a46e4fdab925c622344
-
SHA256
fc1a02b509b8f351ac45bd45efd4e7296b365545a48ffd6a14e8e07bc7189155
-
SHA512
24a726276cc53c5a0d075d1bf930e24b3a1891e0754b17c28a5a35b5677fd792d9adb55e5e0a7fe18f056febb8af4a49a5a0fac33389205d1f4dcc0060422be7
-
SSDEEP
1536:5ilGC+HMax3AZ5GiavgfreZCRIr71mazhAN5TAS:5igLV3SIareERU5mazh3S
Malware Config
Signatures
-
Blocks application from running via registry modification 1 IoCs
Adds application to list of disallowed applications.
Processes:
Patch.exedescription ioc process Set value (int) \REGISTRY\USER\S-1-5-21-1337824034-2731376981-3755436523-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun = "0" Patch.exe -
Disables RegEdit via registry modification 1 IoCs
Processes:
Patch.exedescription ioc process Set value (int) \REGISTRY\USER\S-1-5-21-1337824034-2731376981-3755436523-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools = "0" Patch.exe -
Disables Task Manager via registry modification
-
Disables cmd.exe use via registry modification 1 IoCs
Processes:
Patch.exedescription ioc process Set value (int) \REGISTRY\USER\S-1-5-21-1337824034-2731376981-3755436523-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD = "0" Patch.exe -
Suspicious behavior: EnumeratesProcesses 2 IoCs
Processes:
Patch.exepid process 4616 Patch.exe 4616 Patch.exe -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
Patch.exedescription pid process target process PID 4616 wrote to memory of 4864 4616 Patch.exe wscript.exe PID 4616 wrote to memory of 4864 4616 Patch.exe wscript.exe PID 4616 wrote to memory of 4864 4616 Patch.exe wscript.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\_igetintopc.com_Internet_Download_Manager_6\igetintopc.com_fix\Patch.exe"C:\Users\Admin\AppData\Local\Temp\_igetintopc.com_Internet_Download_Manager_6\igetintopc.com_fix\Patch.exe"1⤵
- Blocks application from running via registry modification
- Disables RegEdit via registry modification
- Disables cmd.exe use via registry modification
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\wscript.exewscript.exe "C:\Users\Admin\AppData\Local\Temp\\UPDT.vbs" /browser:"C:\Program Files\Google\Chrome\Application\chrome.exe" /crkver:"19.7"2⤵
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\UPDT.vbsFilesize
2KB
MD57b18a872d4be22eecf2f95ce5e63ce15
SHA1dfcddf132463dcc697942b32e305ad4aadeb6d98
SHA256e64d9b855b8f02b15626c7e932c0451c07af8e8ebb53bb17626c66e117f50cba
SHA51291533ff0351c9d35408235da164cd5e7149bed91b10c1c624985dcc0e02af2f6ff400181224f5fdcd3b197ff63df3c436f937d8fe79ef955bf9fc999cc13eba5
-
memory/4616-0-0x0000000000400000-0x000000000043D000-memory.dmpFilesize
244KB
-
memory/4616-1-0x0000000000400000-0x000000000043D000-memory.dmpFilesize
244KB