Analysis

  • max time kernel
    149s
  • max time network
    156s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    03-07-2024 05:10

General

  • Target

    3d9fb88bcef5eab71412d7dd1310f00362f982d801267692b28dc34ca45983c6.exe

  • Size

    51KB

  • MD5

    a091532e52927259aa09560e1f788800

  • SHA1

    64528e6344d73dab2930c4ef3fb88c41553d1807

  • SHA256

    3d9fb88bcef5eab71412d7dd1310f00362f982d801267692b28dc34ca45983c6

  • SHA512

    e81567dd459b5f8efd7378d1adc864d5eae7e115f1a348ce7fa9f3a4eb73bc4904a982bff9e12cf54521b87fd95c126e66c446320f7dfefc3af3df594f910b29

  • SSDEEP

    768:+DsBzFlUD/Yop9CwyWOySATV9505sW3fpSwNssG8E4Q4oaKVuE:+DsBzFlQCwyUNTV95ipLW4oaKw

Malware Config

Extracted

Family

cobaltstrike

C2

http://38.6.177.76:4445/jquery-3.3.2.slim.min.js

Attributes
  • user_agent

    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Referer: http://code.jquery.com/ Accept-Encoding: gzip, deflate User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\3d9fb88bcef5eab71412d7dd1310f00362f982d801267692b28dc34ca45983c6.exe
    "C:\Users\Admin\AppData\Local\Temp\3d9fb88bcef5eab71412d7dd1310f00362f982d801267692b28dc34ca45983c6.exe"
    1⤵
      PID:2152

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • memory/2152-1-0x000002886B650000-0x000002886B750000-memory.dmp
      Filesize

      1024KB