Resubmissions
01-07-2024 12:23
240701-pkp6tavcrm 1001-07-2024 12:17
240701-pf8scs1dnf 1001-07-2024 12:12
240701-pdbd3sthnj 1001-07-2024 12:03
240701-n8evbatfll 10Analysis
-
max time kernel
268s -
max time network
270s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
01-07-2024 12:12
Behavioral task
behavioral1
Sample
fix.exe
Resource
win10-20240611-en
Behavioral task
behavioral2
Sample
fix.exe
Resource
win7-20240419-en
Behavioral task
behavioral3
Sample
fix.exe
Resource
win10-20240404-en
Behavioral task
behavioral4
Sample
fix.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
fix.exe
Resource
win11-20240611-en
Errors
General
-
Target
fix.exe
-
Size
35KB
-
MD5
83bbe29b99a54bad48074efb72ce1fcc
-
SHA1
421deeba13130a8eebacc8c7f48f28e6fe8485f2
-
SHA256
99bf031f23b1759702a56ccfc9425f0a063654dcc4a94d8feeb89792c82f3082
-
SHA512
67fe2ac907c297cd3c4d1af7f80257b468bc4e73cab428568ea1238d41cd8c43262765a0b0d43b2accb003901a66e9e7ec162fefda2fd89040697e1e168ac27f
-
SSDEEP
768:ChiLce92aOrsQiUy5FyS9ZL6LOjhibold:ChkceWsQi5FT9ZL6LOjGo7
Malware Config
Extracted
xworm
5.0
20.ip.gl.ply.gg:53765
JCfj6Aifpywc6Ul9
-
Install_directory
%AppData%
-
install_file
svchost.exe
Signatures
-
Detect Xworm Payload 1 IoCs
Processes:
resource yara_rule behavioral3/memory/1452-1-0x0000000000F80000-0x0000000000F90000-memory.dmp family_xworm -
Command and Scripting Interpreter: PowerShell 1 TTPs 4 IoCs
Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.
Processes:
powershell.exepowershell.exepowershell.exepowershell.exepid process 4044 powershell.exe 1920 powershell.exe 4232 powershell.exe 3724 powershell.exe -
Adds Run key to start application 2 TTPs 1 IoCs
Processes:
fix.exedescription ioc process Set value (str) \REGISTRY\USER\S-1-5-21-4106386276-4127174233-3637007343-1000\Software\Microsoft\Windows\CurrentVersion\Run\svchost = "C:\\Users\\Admin\\AppData\\Roaming\\svchost.exe" fix.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies data under HKEY_USERS 15 IoCs
Processes:
LogonUI.exedescription ioc process Set value (data) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent\AccentPalette = a6d8ff0076b9ed00429ce3000078d700005a9e000042750000264200f7630c00 LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent\AccentColorMenu = "4292311040" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\AccentColor = "4292311040" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationColor = "3288365271" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationAfterglow = "3288365271" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationAfterglowBalance = "10" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\EnableWindowColorization = "1" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationGlassAttribute = "1" LogonUI.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Themes\History LogonUI.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM LogonUI.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Themes\History\AutoColor = "0" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Accent\StartColorMenu = "4288567808" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationColorBalance = "89" LogonUI.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\DWM\ColorizationBlurBalance = "1" LogonUI.exe -
Suspicious behavior: EnumeratesProcesses 12 IoCs
Processes:
powershell.exepowershell.exepowershell.exepowershell.exepid process 4044 powershell.exe 4044 powershell.exe 4044 powershell.exe 1920 powershell.exe 1920 powershell.exe 1920 powershell.exe 4232 powershell.exe 4232 powershell.exe 4232 powershell.exe 3724 powershell.exe 3724 powershell.exe 3724 powershell.exe -
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
fix.exepowershell.exepowershell.exepowershell.exedescription pid process Token: SeDebugPrivilege 1452 fix.exe Token: SeDebugPrivilege 4044 powershell.exe Token: SeIncreaseQuotaPrivilege 4044 powershell.exe Token: SeSecurityPrivilege 4044 powershell.exe Token: SeTakeOwnershipPrivilege 4044 powershell.exe Token: SeLoadDriverPrivilege 4044 powershell.exe Token: SeSystemProfilePrivilege 4044 powershell.exe Token: SeSystemtimePrivilege 4044 powershell.exe Token: SeProfSingleProcessPrivilege 4044 powershell.exe Token: SeIncBasePriorityPrivilege 4044 powershell.exe Token: SeCreatePagefilePrivilege 4044 powershell.exe Token: SeBackupPrivilege 4044 powershell.exe Token: SeRestorePrivilege 4044 powershell.exe Token: SeShutdownPrivilege 4044 powershell.exe Token: SeDebugPrivilege 4044 powershell.exe Token: SeSystemEnvironmentPrivilege 4044 powershell.exe Token: SeRemoteShutdownPrivilege 4044 powershell.exe Token: SeUndockPrivilege 4044 powershell.exe Token: SeManageVolumePrivilege 4044 powershell.exe Token: 33 4044 powershell.exe Token: 34 4044 powershell.exe Token: 35 4044 powershell.exe Token: 36 4044 powershell.exe Token: SeDebugPrivilege 1920 powershell.exe Token: SeIncreaseQuotaPrivilege 1920 powershell.exe Token: SeSecurityPrivilege 1920 powershell.exe Token: SeTakeOwnershipPrivilege 1920 powershell.exe Token: SeLoadDriverPrivilege 1920 powershell.exe Token: SeSystemProfilePrivilege 1920 powershell.exe Token: SeSystemtimePrivilege 1920 powershell.exe Token: SeProfSingleProcessPrivilege 1920 powershell.exe Token: SeIncBasePriorityPrivilege 1920 powershell.exe Token: SeCreatePagefilePrivilege 1920 powershell.exe Token: SeBackupPrivilege 1920 powershell.exe Token: SeRestorePrivilege 1920 powershell.exe Token: SeShutdownPrivilege 1920 powershell.exe Token: SeDebugPrivilege 1920 powershell.exe Token: SeSystemEnvironmentPrivilege 1920 powershell.exe Token: SeRemoteShutdownPrivilege 1920 powershell.exe Token: SeUndockPrivilege 1920 powershell.exe Token: SeManageVolumePrivilege 1920 powershell.exe Token: 33 1920 powershell.exe Token: 34 1920 powershell.exe Token: 35 1920 powershell.exe Token: 36 1920 powershell.exe Token: SeDebugPrivilege 4232 powershell.exe Token: SeIncreaseQuotaPrivilege 4232 powershell.exe Token: SeSecurityPrivilege 4232 powershell.exe Token: SeTakeOwnershipPrivilege 4232 powershell.exe Token: SeLoadDriverPrivilege 4232 powershell.exe Token: SeSystemProfilePrivilege 4232 powershell.exe Token: SeSystemtimePrivilege 4232 powershell.exe Token: SeProfSingleProcessPrivilege 4232 powershell.exe Token: SeIncBasePriorityPrivilege 4232 powershell.exe Token: SeCreatePagefilePrivilege 4232 powershell.exe Token: SeBackupPrivilege 4232 powershell.exe Token: SeRestorePrivilege 4232 powershell.exe Token: SeShutdownPrivilege 4232 powershell.exe Token: SeDebugPrivilege 4232 powershell.exe Token: SeSystemEnvironmentPrivilege 4232 powershell.exe Token: SeRemoteShutdownPrivilege 4232 powershell.exe Token: SeUndockPrivilege 4232 powershell.exe Token: SeManageVolumePrivilege 4232 powershell.exe Token: 33 4232 powershell.exe -
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
LogonUI.exepid process 1760 LogonUI.exe -
Suspicious use of WriteProcessMemory 10 IoCs
Processes:
fix.exedescription pid process target process PID 1452 wrote to memory of 4044 1452 fix.exe powershell.exe PID 1452 wrote to memory of 4044 1452 fix.exe powershell.exe PID 1452 wrote to memory of 1920 1452 fix.exe powershell.exe PID 1452 wrote to memory of 1920 1452 fix.exe powershell.exe PID 1452 wrote to memory of 4232 1452 fix.exe powershell.exe PID 1452 wrote to memory of 4232 1452 fix.exe powershell.exe PID 1452 wrote to memory of 3724 1452 fix.exe powershell.exe PID 1452 wrote to memory of 3724 1452 fix.exe powershell.exe PID 1452 wrote to memory of 1300 1452 fix.exe shutdown.exe PID 1452 wrote to memory of 1300 1452 fix.exe shutdown.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\fix.exe"C:\Users\Admin\AppData\Local\Temp\fix.exe"1⤵
- Adds Run key to start application
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\Admin\AppData\Local\Temp\fix.exe'2⤵
- Command and Scripting Interpreter: PowerShell
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess 'fix.exe'2⤵
- Command and Scripting Interpreter: PowerShell
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\Admin\AppData\Roaming\svchost.exe'2⤵
- Command and Scripting Interpreter: PowerShell
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess 'svchost.exe'2⤵
- Command and Scripting Interpreter: PowerShell
- Suspicious behavior: EnumeratesProcesses
-
C:\Windows\SYSTEM32\shutdown.exeshutdown.exe /f /r /t 02⤵
-
C:\Windows\system32\LogonUI.exe"LogonUI.exe" /flags:0x0 /state0:0xa3aed855 /state1:0x41c64e6d1⤵
- Modifies data under HKEY_USERS
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.logFilesize
3KB
MD5ad5cd538ca58cb28ede39c108acb5785
SHA11ae910026f3dbe90ed025e9e96ead2b5399be877
SHA256c9e6cb04d6c893458d5a7e12eb575cf97c3172f5e312b1f63a667cbbc5f0c033
SHA512c066c5d9b276a68fa636647bb29aea05bfa2292217bc77f5324d9c1d93117772ee8277e1f7cff91ec8d6b7c05ca078f929cecfdbb09582522a9067f54740af13
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractiveFilesize
1KB
MD58fe80f306dd23d5b541b162709c5be00
SHA1a5404e0bccb3d2691788027969441a594463ca57
SHA2565cc9a3f462585ba588998e9ec0bcfc8dad5b6454b8e79ccc382284d4b7a27a02
SHA5125133bb980dc20defb6342ef3a04429fe3e6c45eeef6b3e6f1792db0a6cc8f0204f7e93f509b2944a83e4cc041e4b3a3da62e983db08cd1aaf8e1d547b031c3be
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractiveFilesize
1KB
MD573f8bdaf29358d351e54b4748960dcb0
SHA1b485d9f34805dbe48086795914b39d126de052ca
SHA2564571e76dc0babb4a25bc29ae6fb870edc8a27c78a8a90f7274eaa00dab3ba5a0
SHA512688ca34efa87e3712cbecef6963ab73c853d3c2031cda74d220e8b98865803cc0fddbef31a421ce147651c10afa82c4f21c39ba787c13013d3f02305017d42aa
-
C:\Users\Admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractiveFilesize
1KB
MD57ca58499618c4c3856f67265b6875301
SHA1c0682dc05bf53b326d9c4481318fdc21fdf00a09
SHA2566141dac4288ddb0afd9850041dbb93e1a6be7d25816584e61f6438d33d2d4a0c
SHA512b97f72272a821a2ee1de47796f071d33ffada0b779ba68c7927a990a51a1be06de86db28c531d0d56c7b4568cf68e59651f506bc5f35f756870abf88974b3ea6
-
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_ycpkozh5.mhy.ps1Filesize
1B
MD5c4ca4238a0b923820dcc509a6f75849b
SHA1356a192b7913b04c54574d18c28d46e6395428ab
SHA2566b86b273ff34fce19d6b804eff5a3f5747ada4eaa22f1d49c01e52ddb7875b4b
SHA5124dff4ea340f0a823f15d3f4f01ab62eae0e5da579ccb851f8db9dfe84c58b2b37b89903a740e1ee172da793a6e79d560e5f7f9bd058a12a280433ed6fa46510a
-
memory/1452-1-0x0000000000F80000-0x0000000000F90000-memory.dmpFilesize
64KB
-
memory/1452-188-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/1452-187-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/1452-186-0x00007FFD9C953000-0x00007FFD9C954000-memory.dmpFilesize
4KB
-
memory/1452-0-0x00007FFD9C953000-0x00007FFD9C954000-memory.dmpFilesize
4KB
-
memory/1452-185-0x000000001C690000-0x000000001C69C000-memory.dmpFilesize
48KB
-
memory/1452-184-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-10-0x000001EC2B8D0000-0x000001EC2B946000-memory.dmpFilesize
472KB
-
memory/4044-52-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-48-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-25-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-20-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-11-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-9-0x00007FFD9C950000-0x00007FFD9D33C000-memory.dmpFilesize
9.9MB
-
memory/4044-6-0x000001EC2B7A0000-0x000001EC2B7C2000-memory.dmpFilesize
136KB