Analysis

  • max time kernel
    117s
  • max time network
    124s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 12:55

General

  • Target

    Stub.pyc

  • Size

    179KB

  • MD5

    5ff220de07fce3486505f9bdac298e7a

  • SHA1

    5ed4df1e43e9160aa695564d22d2c62f8293b216

  • SHA256

    4e26a9c63f642fe1f707ae78d1482232703797619800cbfe983c5d5f7946d4b3

  • SHA512

    9efbca56b2bb90566d7fb1dc9d490b9c87760334d48fbf5c062165c51629a9b5fa860b6d3ac3a10fc6b2ee367128005af04f417e4c404b32444b95ef649c881f

  • SSDEEP

    3072:dcH3I+7JxnEjXSbvjK2BO34Z7uuG6ZX3e5VKN5wjZ8LptP/hMmfod/9DYO+n:dcHB7f8CfK2B+5VTohfs+n

Score
3/10

Malware Config

Signatures

  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies registry class 9 IoCs
  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs
  • Suspicious use of WriteProcessMemory 7 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    cmd /c C:\Users\Admin\AppData\Local\Temp\Stub.pyc
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:1968
    • C:\Windows\system32\rundll32.exe
      "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\Admin\AppData\Local\Temp\Stub.pyc
      2⤵
      • Modifies registry class
      • Suspicious use of WriteProcessMemory
      PID:2636
      • C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
        "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\Stub.pyc"
        3⤵
        • Suspicious behavior: GetForegroundWindowSpam
        • Suspicious use of SetWindowsHookEx
        PID:624

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
    Filesize

    3KB

    MD5

    a979e3769237dd1b040bbc3e57c0adc2

    SHA1

    449ed68a58a3b933fdc2150d9b85b2b3609a58f7

    SHA256

    b0634fbbd1c8ff0d03588313fc4a5846f6777e26da4d8e75aca0164a7263d96d

    SHA512

    25d897073753ec6ab977d1f6d33cd0cd472fc2a83dd49a80b948e20c67cd1c66ebba30f388aa75a3806c2f0a0495acb99a71b9e358fcf97ea4f4fea0a8675da3