Analysis
-
max time kernel
130s -
max time network
100s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
04-07-2024 12:31
General
-
Target
Wave.exe
-
Size
275KB
-
MD5
19e5a4ce88aa7ef0bab452d3e182f5cd
-
SHA1
e974c7d25e07f391f2dc6a00acdd25ba5f2f0c78
-
SHA256
9625ba4fb35b5e652f398f10f9e4adc115326cd029861bf7ae557df7a53ee274
-
SHA512
d9a4da9d41c19a10680311735fa42ed306eea51032d0bb3c559dacbe9be65cc441bb42544237c799fd2da6e97b4654a3f88b5c4763e2cfbd89911a4d1aec2834
-
SSDEEP
3072:dUjcxEm76PMVyqQH1b2e2TuQZLAsNeDF5nI0PGIj9lua/Obw0hFv2PCWpIdNrY:dL76PMVtQVbpnQ0sNOBTunbw0/5Wpi
Malware Config
Extracted
Family
asyncrat
Version
Venom RAT + HVNC + Stealer + Grabber v6.0.3
Botnet
Default
C2
209.25.140.1:57676
Mutex
Wave
Attributes
-
delay
1
-
install
true
-
install_file
BloxStrap Handler.exe
-
install_folder
%AppData%
aes.plain
Signatures
-
Suspicious use of AdjustPrivilegeToken 43 IoCs
Processes:
Wave.exedescription pid process Token: SeDebugPrivilege 1404 Wave.exe Token: SeIncreaseQuotaPrivilege 1404 Wave.exe Token: SeSecurityPrivilege 1404 Wave.exe Token: SeTakeOwnershipPrivilege 1404 Wave.exe Token: SeLoadDriverPrivilege 1404 Wave.exe Token: SeSystemProfilePrivilege 1404 Wave.exe Token: SeSystemtimePrivilege 1404 Wave.exe Token: SeProfSingleProcessPrivilege 1404 Wave.exe Token: SeIncBasePriorityPrivilege 1404 Wave.exe Token: SeCreatePagefilePrivilege 1404 Wave.exe Token: SeBackupPrivilege 1404 Wave.exe Token: SeRestorePrivilege 1404 Wave.exe Token: SeShutdownPrivilege 1404 Wave.exe Token: SeDebugPrivilege 1404 Wave.exe Token: SeSystemEnvironmentPrivilege 1404 Wave.exe Token: SeRemoteShutdownPrivilege 1404 Wave.exe Token: SeUndockPrivilege 1404 Wave.exe Token: SeManageVolumePrivilege 1404 Wave.exe Token: 33 1404 Wave.exe Token: 34 1404 Wave.exe Token: 35 1404 Wave.exe Token: 36 1404 Wave.exe Token: SeIncreaseQuotaPrivilege 1404 Wave.exe Token: SeSecurityPrivilege 1404 Wave.exe Token: SeTakeOwnershipPrivilege 1404 Wave.exe Token: SeLoadDriverPrivilege 1404 Wave.exe Token: SeSystemProfilePrivilege 1404 Wave.exe Token: SeSystemtimePrivilege 1404 Wave.exe Token: SeProfSingleProcessPrivilege 1404 Wave.exe Token: SeIncBasePriorityPrivilege 1404 Wave.exe Token: SeCreatePagefilePrivilege 1404 Wave.exe Token: SeBackupPrivilege 1404 Wave.exe Token: SeRestorePrivilege 1404 Wave.exe Token: SeShutdownPrivilege 1404 Wave.exe Token: SeDebugPrivilege 1404 Wave.exe Token: SeSystemEnvironmentPrivilege 1404 Wave.exe Token: SeRemoteShutdownPrivilege 1404 Wave.exe Token: SeUndockPrivilege 1404 Wave.exe Token: SeManageVolumePrivilege 1404 Wave.exe Token: 33 1404 Wave.exe Token: 34 1404 Wave.exe Token: 35 1404 Wave.exe Token: 36 1404 Wave.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
memory/1404-0-0x00007FF899AA3000-0x00007FF899AA5000-memory.dmpFilesize
8KB
-
memory/1404-1-0x00000000005E0000-0x000000000062A000-memory.dmpFilesize
296KB
-
memory/1404-3-0x00007FF899AA0000-0x00007FF89A561000-memory.dmpFilesize
10.8MB
-
memory/1404-4-0x00007FF899AA0000-0x00007FF89A561000-memory.dmpFilesize
10.8MB