Analysis
-
max time kernel
27s -
max time network
21s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 08:28
Static task
static1
Behavioral task
behavioral1
Sample
google-setup_104357465463146543.exe
Resource
win7-20240508-en
General
-
Target
google-setup_104357465463146543.exe
-
Size
2.8MB
-
MD5
31c4dd89e640cc438ab60485ed835198
-
SHA1
d8184ae55b594a0b59268979badac691af8ab6ef
-
SHA256
b4b0d125202a42156de8db936fd159a5c4eabc537910f27a9caf8a346b74eb7a
-
SHA512
062624186b156485b4a4892206f38d3a882163d38e6bd7402f03c617c88e94c6552c0877cd76152ed0a21cf14348fc86e30223801d8d70f0781d4f949cf5a22d
-
SSDEEP
49152:bQbAlrYwBHMTJqIyqlJi/s5DVVjgUCnj1IayZlJPx7uJkBwfp4GjWprJMGal7:PrRsTMIyEi05ZlgUCnj2rZfPx7ukBwfB
Malware Config
Signatures
-
Detect Blackmoon payload 1 IoCs
Processes:
resource yara_rule behavioral1/memory/1940-0-0x0000000010000000-0x0000000010246000-memory.dmp family_blackmoon -
Loads dropped DLL 1 IoCs
Processes:
google-setup_104357465463146543.exepid process 1940 google-setup_104357465463146543.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 9 IoCs
Processes:
google-setup_104357465463146543.exepid process 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe 1940 google-setup_104357465463146543.exe
Processes
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
\oieemi\Agghosts.exeFilesize
23KB
MD5a3b2cf55c7370fb05e26a788ede52342
SHA1ee699ba7eee607dc98638fd1bb6ff6be9852d60f
SHA25610b3e08f2a144809ed178e5b7e8382439ffaef8bf1e351cda606453e07ee5c1e
SHA51251bff44116e1d5e7018e60023b882cf1c8f0198b7396b50d1ae5f00f5e93979b9131f897f4f593af27d9f298f56268fa98ec1d301ea49b2cf4e04a7e512342b7
-
memory/1940-0-0x0000000010000000-0x0000000010246000-memory.dmpFilesize
2.3MB