Analysis
-
max time kernel
142s -
max time network
132s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 09:16
Behavioral task
behavioral1
Sample
403518179/TEXT2HTML13/UConvertClass.js
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
403518179/TEXT2HTML13/UConvertClass.js
Resource
win10v2004-20240611-en
Behavioral task
behavioral3
Sample
403518179/TEXT2HTML13/text2html.exe
Resource
win7-20240220-en
Behavioral task
behavioral4
Sample
403518179/TEXT2HTML13/text2html.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
403518179/flashget1.exe
Resource
win7-20240508-en
Behavioral task
behavioral6
Sample
403518179/flashget1.exe
Resource
win10v2004-20240508-en
General
-
Target
403518179/flashget1.exe
-
Size
49KB
-
MD5
6c09ec31b87e8c4c37a571de86cefebb
-
SHA1
12dbce9f388162a27de2bc757863eac1cc3f3d6b
-
SHA256
92449ef542dd41fc40c8c9de928588f590694f16e271a18a17d2c5d7c70faed9
-
SHA512
1a793f975db781544976ee4c236c49a82138824da48e57957b163697e20fab5ba8d1fc79864864451a02a9dc3e4439ca499ff01d603e6fe13bfe7a2938e1d543
-
SSDEEP
1536:0kh1tUlXu37pA828Nz9uNizpDuD4x/AYxJ:rh1alXu3DF9lzpn/Am
Malware Config
Signatures
-
Executes dropped EXE 1 IoCs
Processes:
MiniServer.exepid process 1728 MiniServer.exe -
Drops file in System32 directory 1 IoCs
Processes:
MiniServer.exedescription ioc process File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat MiniServer.exe -
Drops file in Windows directory 2 IoCs
Processes:
flashget1.exedescription ioc process File opened for modification C:\Windows\MiniServer.exe flashget1.exe File created C:\Windows\MiniServer.exe flashget1.exe -
Modifies data under HKEY_USERS 30 IoCs
Processes:
MiniServer.exedescription ioc process Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\WpadDecisionReason = "1" MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MiniServer.exe = "MiniServer.exe" MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet = "0" MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings = 4600000002000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\WpadDecision = "0" MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix = "Cookie:" MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\WpadDecisionTime = 80ce736c97cbda01 MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49\WpadDecisionTime = a0d5c19c97cbda01 MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect = "1" MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387} MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49\WpadDecision = "0" MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\82-18-08-dd-ed-49 MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix = "Visited:" MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49\WpadDetectedUrl MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\WpadDecisionTime = a0d5c19c97cbda01 MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable = "0" MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings = 4600000002000000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{8B143C40-E03D-411D-A9CA-EB08DC283387}\WpadNetworkName = "Network 3" MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49 MiniServer.exe Set value (int) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49\WpadDecisionReason = "1" MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\SoftWare\Microsoft\Windows\CurrentVersion\Run MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings = 4600000004000000090000000000000000000000000000000400000000000000000000000000000000000000000000000000000001000000020000000a7f002e000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections MiniServer.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad MiniServer.exe Set value (str) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings = 4600000003000000090000000000000000000000000000000400000000000000000000000000000000000000000000000000000001000000020000000a7f002e000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 MiniServer.exe Set value (data) \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\82-18-08-dd-ed-49\WpadDecisionTime = 80ce736c97cbda01 MiniServer.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\403518179\flashget1.exe"C:\Users\Admin\AppData\Local\Temp\403518179\flashget1.exe"1⤵
- Drops file in Windows directory
-
C:\Windows\MiniServer.exeC:\Windows\MiniServer.exe1⤵
- Executes dropped EXE
- Drops file in System32 directory
- Modifies data under HKEY_USERS
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Windows\MiniServer.exeFilesize
49KB
MD56c09ec31b87e8c4c37a571de86cefebb
SHA112dbce9f388162a27de2bc757863eac1cc3f3d6b
SHA25692449ef542dd41fc40c8c9de928588f590694f16e271a18a17d2c5d7c70faed9
SHA5121a793f975db781544976ee4c236c49a82138824da48e57957b163697e20fab5ba8d1fc79864864451a02a9dc3e4439ca499ff01d603e6fe13bfe7a2938e1d543
-
memory/1728-5-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/1728-7-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/1728-10-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/1728-13-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/1728-16-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/1728-18-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB
-
memory/2064-4-0x0000000000400000-0x000000000041D000-memory.dmpFilesize
116KB