Analysis

  • max time kernel
    140s
  • max time network
    118s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 07:25

General

  • Target

    USBDiskStorageFormatTool_v5.1_/USBDiskStorageFormatTool_v5.1_/USB Format Tool 5.1-chs.exe

  • Size

    1.0MB

  • MD5

    e533291b2492577abde6de8be6741e6a

  • SHA1

    e398062b0e1088eec767d60e914960c4d5e67755

  • SHA256

    2040460ce1f9a0b62bae64c24cc540a06b55c942856c79464904acc088237a82

  • SHA512

    a51197bbfcbcf8ec2a86cc7679a65536fcea443b4273b2fb3517c5890cec82e46a145a42e5a3b329ea82275f4bfd62455e54e6edf7f897902dcc5ccdefd71436

  • SSDEEP

    12288:lHEKGx8+6uHmMNjmxATk2N8I5KldgRlN1n8E6czUbto7tjoHl:ez8ro1oATh/K/g9t8E3zUb+CHl

Score
6/10

Malware Config

Signatures

  • Writes to the Master Boot Record (MBR) 1 TTPs 1 IoCs

    Bootkits write to the MBR to gain persistence at a level below the operating system.

Processes

  • C:\Users\Admin\AppData\Local\Temp\USBDiskStorageFormatTool_v5.1_\USBDiskStorageFormatTool_v5.1_\USB Format Tool 5.1-chs.exe
    "C:\Users\Admin\AppData\Local\Temp\USBDiskStorageFormatTool_v5.1_\USBDiskStorageFormatTool_v5.1_\USB Format Tool 5.1-chs.exe"
    1⤵
    • Writes to the Master Boot Record (MBR)
    PID:288

Network

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Replay Monitor

Loading Replay Monitor...

Downloads

  • memory/288-0-0x0000000000230000-0x0000000000231000-memory.dmp
    Filesize

    4KB

  • memory/288-1-0x0000000000400000-0x000000000050E000-memory.dmp
    Filesize

    1.1MB

  • memory/288-3-0x0000000000230000-0x0000000000231000-memory.dmp
    Filesize

    4KB