Analysis

  • max time kernel
    2s
  • platform
    windows11-21h2_x64
  • resource
    win11-20240611-en
  • resource tags

    arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system
  • submitted
    01-07-2024 11:05

General

  • Target

    Python-Exe-Decompiler-main/decompile.py

  • Size

    10KB

  • MD5

    c79e7ebf443590e54ff39ae8eef2b458

  • SHA1

    d129304892a3ea1999cfa0fc379b0cc1f8d7ed86

  • SHA256

    b6e60f539595c544b035683b630389c7b29e4f96fdbd51a81cc1cdd488d55973

  • SHA512

    478e51418cfa5e2cac3f312549e79c94859c5b4b87db478f62ab7af5e4aab1218db6f0485c5f63d67f386b09ab32613b6a7b89ec38808e46398690222fb2aca4

  • SSDEEP

    192:ssfbOw0uhBGUZXW5PcQ141v2MlKHh8rzKXUJM:ssfbOqBQ141v2MKMzUU6

Score
3/10

Malware Config

Signatures

  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies registry class 2 IoCs
  • Suspicious use of SetWindowsHookEx 1 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    cmd /c C:\Users\Admin\AppData\Local\Temp\Python-Exe-Decompiler-main\decompile.py
    1⤵
    • Modifies registry class
    PID:4900
  • C:\Windows\system32\OpenWith.exe
    C:\Windows\system32\OpenWith.exe -Embedding
    1⤵
    • Modifies registry class
    • Suspicious use of SetWindowsHookEx
    PID:4896

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads