Analysis

  • max time kernel
    120s
  • max time network
    128s
  • platform
    windows7_x64
  • resource
    win7-20240704-en
  • resource tags

    arch:x64arch:x86image:win7-20240704-enlocale:en-usos:windows7-x64system
  • submitted
    04-07-2024 18:56

General

  • Target

    2024-07-04_62a60e06e2da962a2d9ac148b26af7e9_magniber_metamorfo.exe

  • Size

    13.0MB

  • MD5

    62a60e06e2da962a2d9ac148b26af7e9

  • SHA1

    a2ce127ced9ba0a2cdbfb8c390a05d688a7084a4

  • SHA256

    965a87d860db24b63d1680148f416549e0792d9ed66eac2713dcfb11c1e5749e

  • SHA512

    cb591311de86df120454428bb8827310a0fe6feaec52c12c39c5f49a8f6c83c8fed25fe56a0242ff2838cd719d19d0718fdc403ba10b2e466d0aac7a380be22c

  • SSDEEP

    196608:onC20D8MFxKhdj9O0AoHWrXoLGI+zNLdmODAH06tWnJ1ebrqNU2R73js:onA8ywhdRvbWr49hFH06ttbrqNN3g

Score
1/10

Malware Config

Signatures

  • Modifies registry class 3 IoCs
  • Modifies system certificate store 2 TTPs 10 IoCs
  • Suspicious behavior: EnumeratesProcesses 2 IoCs
  • Suspicious use of SetWindowsHookEx 3 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\2024-07-04_62a60e06e2da962a2d9ac148b26af7e9_magniber_metamorfo.exe
    "C:\Users\Admin\AppData\Local\Temp\2024-07-04_62a60e06e2da962a2d9ac148b26af7e9_magniber_metamorfo.exe"
    1⤵
    • Modifies registry class
    • Modifies system certificate store
    • Suspicious behavior: EnumeratesProcesses
    • Suspicious use of SetWindowsHookEx
    PID:2256

Network

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    75e8af9350b51142307aafe881eadf8c

    SHA1

    9ca526a690a3a19ebd61678b62f807aa04160164

    SHA256

    a11a9319ff3b0008acfcf09c2d1af850a84c2c69c0dc6c2c3e6beea103f7ff12

    SHA512

    2fdf25d930056afbfa5349961ef49faef1d14a0f5be14eb0e5cc137814a63e3c9da5b943aa0ce561f4264341058db98a583e2b2206b9c6cd989af634b787df21

  • C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
    Filesize

    342B

    MD5

    042ae6a43523b8b5ef2f69ba33c99d31

    SHA1

    f56369ebb7396f99a6d1daef06c7a180db4c1d67

    SHA256

    0b945f2103892be42d54b56d1339547472b62d4294988549c2e7e2b29db00c26

    SHA512

    e28c7822d7103cd1850262cc13860229c6e1ebc8eaa84643cfe002fe0df5035aa2b6eaf51c197ac93841cd92045d7dd9669fb3ef8a5d96326753823aaf256f51

  • C:\Users\Admin\AppData\Local\Temp\Cab3036.tmp
    Filesize

    70KB

    MD5

    49aebf8cbd62d92ac215b2923fb1b9f5

    SHA1

    1723be06719828dda65ad804298d0431f6aff976

    SHA256

    b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f

    SHA512

    bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b

  • C:\Users\Admin\AppData\Local\Temp\Tar30E5.tmp
    Filesize

    181KB

    MD5

    4ea6026cf93ec6338144661bf1202cd1

    SHA1

    a1dec9044f750ad887935a01430bf49322fbdcb7

    SHA256

    8efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8

    SHA512

    6c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b