Analysis

  • max time kernel
    122s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    03-07-2024 03:33

General

  • Target

    PySilon-malware-3.7.5/resources/discord_token_grabber.py

  • Size

    12KB

  • MD5

    32c812c4d73d3e3e2fb9ae35e6262dbe

  • SHA1

    37525639cc07d60bf39ae7c50be248b7ae7832e3

  • SHA256

    09b16591c62127f39c138f3d36537d5577042ee9349bd9bca075a0c5bb13c823

  • SHA512

    a1f8f0e08bcfd36b6fce4c3d7e9322692e57034f918de3ff42bbc6d30fe6a59e01c52c4276235a23000e3b1f230b44224ebfc34ef466d6c410081c28bea8a139

  • SSDEEP

    384:xP2g/IOwWb1IdsvxtMwv3tMwvQk6fi3sY5Gl4:1IHaZt7vt7YVfi3s7l4

Score
3/10

Malware Config

Signatures

  • Enumerates physical storage devices 1 TTPs

    Attempts to interact with connected storage/optical drive(s).

  • Modifies registry class 9 IoCs
  • Suspicious behavior: GetForegroundWindowSpam 1 IoCs
  • Suspicious use of SetWindowsHookEx 2 IoCs
  • Suspicious use of WriteProcessMemory 7 IoCs

Processes

  • C:\Windows\system32\cmd.exe
    cmd /c C:\Users\Admin\AppData\Local\Temp\PySilon-malware-3.7.5\resources\discord_token_grabber.py
    1⤵
    • Suspicious use of WriteProcessMemory
    PID:1700
    • C:\Windows\system32\rundll32.exe
      "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\Admin\AppData\Local\Temp\PySilon-malware-3.7.5\resources\discord_token_grabber.py
      2⤵
      • Modifies registry class
      • Suspicious use of WriteProcessMemory
      PID:2652
      • C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
        "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\PySilon-malware-3.7.5\resources\discord_token_grabber.py"
        3⤵
        • Suspicious behavior: GetForegroundWindowSpam
        • Suspicious use of SetWindowsHookEx
        PID:2888

Network

MITRE ATT&CK Matrix ATT&CK v13

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
    Filesize

    3KB

    MD5

    73a97ce37160a46cbf96a713953906c5

    SHA1

    85c56b061b91428ee06fc87e97c7b1ccb4742ad3

    SHA256

    d1e4a8953937112493276b57b9aa8c8d33d5ecc19c89b69a83699d2612d5d9ce

    SHA512

    9f37e0b7bb00c2715b61e20b46568f3761bebe2a20f8da98416073a5afa90f3732b22daba01a88f32e1c892613dc50b1125d5827e0b3daba55d818970b09847e