Analysis
-
max time kernel
61s -
max time network
66s -
platform
windows11-21h2_x64 -
resource
win11-20240611-en -
resource tags
arch:x64arch:x86image:win11-20240611-enlocale:en-usos:windows11-21h2-x64system -
submitted
04-07-2024 01:35
Static task
static1
URLScan task
urlscan1
Behavioral task
behavioral1
Sample
https://u.to/BI3CIA
Resource
win11-20240611-en
General
-
Target
https://u.to/BI3CIA
Malware Config
Signatures
-
Enumerates system info in registry 2 TTPs 3 IoCs
Processes:
msedge.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS msedge.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemManufacturer msedge.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemProductName msedge.exe -
Suspicious behavior: EnumeratesProcesses 8 IoCs
Processes:
msedge.exemsedge.exemsedge.exeidentity_helper.exepid process 2228 msedge.exe 2228 msedge.exe 1816 msedge.exe 1816 msedge.exe 1096 msedge.exe 1096 msedge.exe 1760 identity_helper.exe 1760 identity_helper.exe -
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary 7 IoCs
Processes:
msedge.exepid process 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe -
Suspicious use of FindShellTrayWindow 25 IoCs
Processes:
msedge.exepid process 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe -
Suspicious use of SendNotifyMessage 12 IoCs
Processes:
msedge.exepid process 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe 1816 msedge.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
msedge.exedescription pid process target process PID 1816 wrote to memory of 2572 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 2572 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 3312 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 2228 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 2228 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe PID 1816 wrote to memory of 5096 1816 msedge.exe msedge.exe
Processes
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://u.to/BI3CIA1⤵
- Enumerates system info in registry
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=90.0.4430.212 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=90.0.818.66 --initial-client-data=0x100,0x104,0x108,0xdc,0x10c,0x7ffaaa3e3cb8,0x7ffaaa3e3cc8,0x7ffaaa3e3cd82⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --gpu-preferences=SAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4AAAAAAAAAHgAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAAIAAAAAAAAAAgAAAAAAAAA --mojo-platform-channel-handle=1876 /prefetch:22⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2392 /prefetch:32⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2700 /prefetch:82⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3264 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3280 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4068 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5308 /prefetch:82⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\identity_helper.exe"C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.66\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5368 /prefetch:82⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=5104 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --instant-process --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4804 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4480 /prefetch:12⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --field-trial-handle=1904,4708804388200679805,13814335755267452342,131072 --lang=en-US --disable-client-side-phishing-detection --instant-process --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=13 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4636 /prefetch:12⤵
-
C:\Windows\System32\CompPkgSrv.exeC:\Windows\System32\CompPkgSrv.exe -Embedding1⤵
-
C:\Windows\System32\CompPkgSrv.exeC:\Windows\System32\CompPkgSrv.exe -Embedding1⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datFilesize
152B
MD5f717f56b5d8e2e057c440a5a81043662
SHA10ad6c9bbd28dab5c9664bad04db95fd50db36b3f
SHA2564286cd3f23251d0a607e47eccb5e0f4af8542d38b32879d2db2ab7f4e6031945
SHA51261e263935d51028ec0aab51b938b880945a950cec9635a0dafddf795658ea0a2dfcf9cfc0cab5459b659bb7204347b047a5c6b924fabea44ce389b1cbb9867d6
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datFilesize
152B
MD5196eaa9f7a574c29bd419f9d8c2d9349
SHA119982d15d1e2688903b0a3e53a8517ab537b68ed
SHA256df1e96677bcfffe5044826aa14a11e85ef2ebb014ee9e890e723a14dc5f31412
SHA512e066d74da36a459c19db30e68b703ec9f92019f2d5f24fd476a5fd3653c0b453871e2c08cdc47f2b4d4c4be19ff99e6ef3956d93b2d7d0a69645577d44125ac7
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\Code Cache\js\index-dir\the-real-indexFilesize
480B
MD5a822be41a275266d4c8f95017181ee68
SHA101935ef5bc3c740829ff8795426d47784e40f3a7
SHA256b6c817b2cdc7a2d5d8c3d8dd6e0d6cedbcb796088f39d5f3c1add3690bf3bd71
SHA5120335e21cd45ff961565c238f24ad00c8acad0024d278252a323aa2a46004a9cc14b425b7a4998422946aa80ac362b5533bb8733072e77ea73f75b2f182d77ea1
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\PreferencesFilesize
6KB
MD5001a8347cce56b20aaa9e8640237844c
SHA1ed3d49cc0a492b063acdc74d9974ba93b0a01852
SHA256f6df0c27259fbc52147f1dab67a25bcfced3ce5b6d478dfe781fe73b51ae193b
SHA512a05838f956a6af5c618ff15d0a86fd434df99d994d9e2a25a4f7d2795dd3028046870b0ef1f71495db08b58b4f43123c253dc4e21ae6f7087d2d70b3baa18d07
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\PreferencesFilesize
6KB
MD5e500b58a6415199bbdd2b698a34ad6b7
SHA1c1b5d2a3dc533aa99015c462a18281bb22e85dcb
SHA2564b80e3375ea1c773560b5f997094a0e66c8f1696be5e1ab93e0ffc2ab638353d
SHA51290976b14de083fc39ecef0f67dfd00681c06975266d8df651114efb93f2240a5cf6cec76a4492f5ece2ecc285dba2bd8d5ea628f1dcec149c448f4605c54acbb
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\c9f7936d-4097-488b-8269-497b9e6102fa.tmpFilesize
5KB
MD539890faa1880730f3f8ad1bba69a688a
SHA1596df11a3cd995185dc8359c4712e2aee37bc398
SHA256fb0e990692cc049f2d208d1048e07a4c59f7b6d08ba3f873884d7450d919434c
SHA5128aeb693c871d9e11ce86f39a745072a056414ff09ba616566443024ace435a74273c955882ebf7542cca1e5c5f1d899c8462b071a97b3ff31c8d366d77ea43ab
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\CURRENTFilesize
16B
MD546295cac801e5d4857d09837238a6394
SHA144e0fa1b517dbf802b18faf0785eeea6ac51594b
SHA2560f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
SHA5128969402593f927350e2ceb4b5bc2a277f3754697c1961e3d6237da322257fbab42909e1a742e22223447f3a4805f8d8ef525432a7c3515a549e984d3eff72b23
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Default\data_reduction_proxy_leveldb\CURRENTFilesize
16B
MD5206702161f94c5cd39fadd03f4014d98
SHA1bd8bfc144fb5326d21bd1531523d9fb50e1b600a
SHA2561005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
SHA5120af09f26941b11991c750d1a2b525c39a8970900e98cba96fd1b55dbf93fee79e18b8aab258f48b4f7bda40d059629bc7770d84371235cdb1352a4f17f80e145
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Local StateFilesize
11KB
MD5ab623277e0d4e3eb0337051d40fd4fcb
SHA1073054a31c6576e6ea4d137a27e3de08fda5ba11
SHA256b2877438ee8d667a7c695440566f191c75b6f3c3b0a77d6d8242af0283728dc1
SHA512997f5920ab69fe85938427e994b07be3d64b0aa3bed34ac3c8e2d13d0a0cb52c4b443673bd38fca58138044da30ff8af466b0199b469d3e96cc1bfe70ea940e6
-
C:\Users\Admin\AppData\Local\Microsoft\Edge\User Data\Local StateFilesize
11KB
MD5860abfde2bedca0a8202e0c08098a820
SHA16e71903eb589e6293c23d3c9fbcbaa16cb20f187
SHA256985c7612e0c25332cfc87f7470ba3808c168d8706972f5eef78d73fd801e2b87
SHA512e47de3de243fb1f5c738feb639424cf4717f908e7331e39dfc57fedf4095c798075fa00226890fee6f1113d6109f85bfb7fa5b700c7d46b68e60bacc25b5d43b
-
\??\pipe\LOCAL\crashpad_1816_UUCEFVGNHRURLQIOMD5
d41d8cd98f00b204e9800998ecf8427e
SHA1da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA512cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e