Analysis

  • max time kernel
    117s
  • max time network
    124s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 16:22

General

  • Target

    42efa7b100db85b31b900dbf8b89f35a894bf3805a095bc4e9f957982e7caf46.exe

  • Size

    6.1MB

  • MD5

    a3314c6acf0ac7cd9e0117dc9e9ba01a

  • SHA1

    695da82e6cd5c569cbd9a020ffee4a85175d3c2d

  • SHA256

    42efa7b100db85b31b900dbf8b89f35a894bf3805a095bc4e9f957982e7caf46

  • SHA512

    e7c5db318f660be8556ede74211a71f146af27578d46a714c95bb1258ec675248924dcca99e14bd7f687e380cc390bee95c6bb0669721bf854195c324060f852

  • SSDEEP

    98304:Nw99p6pzBrWtG6E61pLVvnTQZ9ZfQfhGe6HJsH/ocMxzmUdC5hopYIGElv00e:Nw9zctWtwULVvnE90hMsAc6zI5MJFv0

Score
7/10

Malware Config

Signatures

  • VMProtect packed file 5 IoCs

    Detects executables packed with VMProtect commercial packer.

  • Program crash 1 IoCs
  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of AdjustPrivilegeToken 49 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs
  • Suspicious use of WriteProcessMemory 4 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\42efa7b100db85b31b900dbf8b89f35a894bf3805a095bc4e9f957982e7caf46.exe
    "C:\Users\Admin\AppData\Local\Temp\42efa7b100db85b31b900dbf8b89f35a894bf3805a095bc4e9f957982e7caf46.exe"
    1⤵
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of AdjustPrivilegeToken
    • Suspicious use of SetWindowsHookEx
    • Suspicious use of WriteProcessMemory
    PID:1932
    • C:\Windows\SysWOW64\WerFault.exe
      C:\Windows\SysWOW64\WerFault.exe -u -p 1932 -s 928
      2⤵
      • Program crash
      PID:2472
  • C:\Windows\SysWOW64\DllHost.exe
    C:\Windows\SysWOW64\DllHost.exe /Processid:{3F6B5E16-092A-41ED-930B-0B4125D91D4E}
    1⤵
      PID:2776

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/1932-29-0x00000000002A0000-0x00000000002A1000-memory.dmp
      Filesize

      4KB

    • memory/1932-37-0x0000000000400000-0x0000000001082000-memory.dmp
      Filesize

      12.5MB

    • memory/1932-35-0x00000000002B0000-0x00000000002B1000-memory.dmp
      Filesize

      4KB

    • memory/1932-33-0x00000000002B0000-0x00000000002B1000-memory.dmp
      Filesize

      4KB

    • memory/1932-31-0x00000000002B0000-0x00000000002B1000-memory.dmp
      Filesize

      4KB

    • memory/1932-30-0x0000000000735000-0x0000000000A6F000-memory.dmp
      Filesize

      3.2MB

    • memory/1932-27-0x00000000002A0000-0x00000000002A1000-memory.dmp
      Filesize

      4KB

    • memory/1932-24-0x0000000000210000-0x0000000000211000-memory.dmp
      Filesize

      4KB

    • memory/1932-22-0x0000000000210000-0x0000000000211000-memory.dmp
      Filesize

      4KB

    • memory/1932-19-0x0000000000200000-0x0000000000201000-memory.dmp
      Filesize

      4KB

    • memory/1932-17-0x0000000000200000-0x0000000000201000-memory.dmp
      Filesize

      4KB

    • memory/1932-14-0x00000000001F0000-0x00000000001F1000-memory.dmp
      Filesize

      4KB

    • memory/1932-12-0x00000000001F0000-0x00000000001F1000-memory.dmp
      Filesize

      4KB

    • memory/1932-9-0x00000000001E0000-0x00000000001E1000-memory.dmp
      Filesize

      4KB

    • memory/1932-7-0x00000000001E0000-0x00000000001E1000-memory.dmp
      Filesize

      4KB

    • memory/1932-5-0x00000000001E0000-0x00000000001E1000-memory.dmp
      Filesize

      4KB

    • memory/1932-4-0x00000000001C0000-0x00000000001C1000-memory.dmp
      Filesize

      4KB

    • memory/1932-2-0x00000000001C0000-0x00000000001C1000-memory.dmp
      Filesize

      4KB

    • memory/1932-0-0x00000000001C0000-0x00000000001C1000-memory.dmp
      Filesize

      4KB

    • memory/1932-39-0x0000000000400000-0x0000000001082000-memory.dmp
      Filesize

      12.5MB

    • memory/1932-46-0x0000000000400000-0x0000000001082000-memory.dmp
      Filesize

      12.5MB

    • memory/1932-47-0x0000000000400000-0x0000000001082000-memory.dmp
      Filesize

      12.5MB

    • memory/1932-51-0x0000000000400000-0x0000000001082000-memory.dmp
      Filesize

      12.5MB

    • memory/1932-52-0x0000000000735000-0x0000000000A6F000-memory.dmp
      Filesize

      3.2MB