Overview
overview
10Static
static
32024 Arnol...ns.exe
windows10-2004-x64
10AMMonitori...er.dll
windows10-2004-x64
1EppManifest.dll
windows10-2004-x64
1ImagingBase.dll
windows7-x64
1ImagingBase.dll
windows10-2004-x64
1MpAsDesc.dll
windows10-2004-x64
1MpAzSubmit.dll
windows10-2004-x64
1MpClient.dll
windows7-x64
10MpClient.dll
windows10-2004-x64
10MpCommu.dll
windows10-2004-x64
1MpDetours.dll
windows10-2004-x64
1MpDetoursC...or.dll
windows10-2004-x64
1MpEvMsg.dll
windows10-2004-x64
1MpOAV.dll
windows10-2004-x64
1MpProvider.dll
windows10-2004-x64
1MpRtp.dll
windows10-2004-x64
1MpSvc.dll
windows10-2004-x64
1MsMpCom.dll
windows10-2004-x64
1MsMpLics.dll
windows10-2004-x64
1Protection...nt.dll
windows10-2004-x64
1endpointdlp.dll
windows10-2004-x64
1Analysis
-
max time kernel
125s -
max time network
134s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 16:27
Static task
static1
Behavioral task
behavioral1
Sample
2024 Arnold Machinery Trial Order Company Profile Specifications.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral2
Sample
AMMonitoringProvider.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
EppManifest.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral4
Sample
ImagingBase.dll
Resource
win7-20240419-en
Behavioral task
behavioral5
Sample
ImagingBase.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral6
Sample
MpAsDesc.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
MpAzSubmit.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral8
Sample
MpClient.dll
Resource
win7-20240508-en
Behavioral task
behavioral9
Sample
MpClient.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral10
Sample
MpCommu.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
MpDetours.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral12
Sample
MpDetoursCopyAccelerator.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
MpEvMsg.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral14
Sample
MpOAV.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
MpProvider.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral16
Sample
MpRtp.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
MpSvc.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral18
Sample
MsMpCom.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
MsMpLics.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral20
Sample
ProtectionManagement.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
endpointdlp.dll
Resource
win10v2004-20240508-en
General
-
Target
MpAsDesc.dll
-
Size
204KB
-
MD5
ba2b29557ff5f4f3a7a55306d25b8d2b
-
SHA1
ca5dd5da467c755daa8be068397936c8de41057d
-
SHA256
5bf78317f21a79e0e6d48d68c30532888a7f5b3b629ef240733befff3619e9a2
-
SHA512
00b643281b0b49113fc6aa7ff1d234089c184a4080213065d96a13e39fedfc6f066d313469726d373a8c962e730a264226cd682d41f03a2e0ca15e8eb4f5d30e
-
SSDEEP
6144:vmiTVVmVVV8VVNVVVcVVVxVVVPVVlVVVRVVVtVVWV60jVLVVOVVUVZVVVVVjVVJ/:Nf
Malware Config
Signatures
Processes
-
C:\Windows\system32\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\MpAsDesc.dll,#11⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --field-trial-handle=4200,i,13035806169561352434,1332896185314862791,262144 --variations-seed-version --mojo-platform-channel-handle=4120 /prefetch:81⤵