Analysis
-
max time kernel
120s -
max time network
121s -
platform
windows7_x64 -
resource
win7-20240704-en -
resource tags
arch:x64arch:x86image:win7-20240704-enlocale:en-usos:windows7-x64system -
submitted
05-07-2024 01:54
Behavioral task
behavioral1
Sample
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe
Resource
win7-20240704-en
Behavioral task
behavioral2
Sample
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe
Resource
win10v2004-20240704-en
General
-
Target
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe
-
Size
2.3MB
-
MD5
11ec2263423a6c9c8ca33fe4c021e9a4
-
SHA1
187934d7646cc1d33c923d1fbb0b385adbc411d1
-
SHA256
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7
-
SHA512
d86b834a6554be6984222ddc926675e11df6d128841d51baba2f3b0e38ffcb08fdb7c01918a28c5db36c6c6c6799b8883a1131a9b41c5dc78a089c99151da4bf
-
SSDEEP
49152:q/OAn5V6k2DyNqLRN02tf1YkbY8TwHW47AFr3aT:uOs5VUCZ2tf1Ykk8TwHXerKT
Malware Config
Signatures
-
DcRat
DarkCrystal(DC) is a new .NET RAT active since June 2019 capable of loading additional plugins.
-
Process spawned unexpected child process 45 IoCs
This typically indicates the parent process was compromised via an exploit or macro.
Processes:
schtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exedescription pid pid_target process target process Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2760 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2184 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 648 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2032 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1972 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1732 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2456 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 800 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1868 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1568 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1676 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1672 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1748 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1276 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1740 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 836 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2972 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1684 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2584 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1608 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2064 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2060 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2300 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1768 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1200 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1172 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1216 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2148 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2908 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 596 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2008 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2588 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2664 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2620 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2644 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2736 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2904 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2500 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1532 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 944 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 524 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2724 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2820 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 2800 2068 schtasks.exe Parent C:\Windows\system32\wbem\wmiprvse.exe is not expected to spawn this process 1824 2068 schtasks.exe -
Processes:
resource yara_rule behavioral1/memory/2368-1-0x00000000013B0000-0x0000000001602000-memory.dmp dcrat C:\Users\Public\Idle.exe dcrat behavioral1/memory/3000-46-0x0000000000030000-0x0000000000282000-memory.dmp dcrat -
Executes dropped EXE 1 IoCs
Processes:
Idle.exepid process 3000 Idle.exe -
Drops file in Program Files directory 8 IoCs
Processes:
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exedescription ioc process File created C:\Program Files\Windows Media Player\dwm.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files\Windows Media Player\6cb0b6c459d5d3 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\services.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\c5b4cb5e9653cc e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files\7-Zip\Lang\lsm.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files\7-Zip\Lang\101b941d020240 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\fr\winlogon.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\fr\cc11b995f2a76d e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe -
Drops file in Windows directory 9 IoCs
Processes:
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exedescription ioc process File created C:\Windows\CSC\27d1bcfc3c54e0 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\CSC\System.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\Branding\Basebrd\en-US\csrss.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\Branding\Basebrd\en-US\886983d96e3d3e e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\ShellNew\csrss.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\ShellNew\886983d96e3d3e e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\debug\WIA\dllhost.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\debug\WIA\5940a34987c991 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe File created C:\Windows\winsxs\wow64_microsoft-windows-i..onal-keyboard-kbdbr_31bf3856ad364e35_6.1.7600.16385_none_dc997fab6806edac\services.exe e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Scheduled Task/Job: Scheduled Task 1 TTPs 45 IoCs
Schtasks is often used by malware for persistence or to perform post-infection execution.
Processes:
schtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exeschtasks.exepid process 2620 schtasks.exe 1276 schtasks.exe 2060 schtasks.exe 1768 schtasks.exe 2148 schtasks.exe 2008 schtasks.exe 2588 schtasks.exe 2760 schtasks.exe 1172 schtasks.exe 944 schtasks.exe 2644 schtasks.exe 2736 schtasks.exe 1732 schtasks.exe 1676 schtasks.exe 1608 schtasks.exe 2300 schtasks.exe 2908 schtasks.exe 2664 schtasks.exe 2800 schtasks.exe 1748 schtasks.exe 2500 schtasks.exe 2184 schtasks.exe 648 schtasks.exe 2032 schtasks.exe 1568 schtasks.exe 2584 schtasks.exe 1216 schtasks.exe 1672 schtasks.exe 836 schtasks.exe 596 schtasks.exe 2724 schtasks.exe 2820 schtasks.exe 1824 schtasks.exe 1972 schtasks.exe 2456 schtasks.exe 800 schtasks.exe 2972 schtasks.exe 2064 schtasks.exe 2904 schtasks.exe 1868 schtasks.exe 1740 schtasks.exe 1684 schtasks.exe 1200 schtasks.exe 1532 schtasks.exe 524 schtasks.exe -
Suspicious behavior: EnumeratesProcesses 8 IoCs
Processes:
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exeIdle.exepid process 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe 3000 Idle.exe -
Suspicious use of AdjustPrivilegeToken 2 IoCs
Processes:
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exeIdle.exedescription pid process Token: SeDebugPrivilege 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe Token: SeDebugPrivilege 3000 Idle.exe -
Suspicious use of WriteProcessMemory 3 IoCs
Processes:
e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exedescription pid process target process PID 2368 wrote to memory of 3000 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe Idle.exe PID 2368 wrote to memory of 3000 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe Idle.exe PID 2368 wrote to memory of 3000 2368 e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe Idle.exe -
Uses Task Scheduler COM API 1 TTPs
The Task Scheduler COM API can be used to schedule applications to run on boot or at set times.
Processes
-
C:\Users\Admin\AppData\Local\Temp\e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe"C:\Users\Admin\AppData\Local\Temp\e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe"1⤵
- Drops file in Program Files directory
- Drops file in Windows directory
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Public\Idle.exe"C:\Users\Public\Idle.exe"2⤵
- Executes dropped EXE
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7e" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7e" /sc MINUTE /mo 6 /tr "'C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrssc" /sc MINUTE /mo 11 /tr "'C:\Windows\Branding\Basebrd\en-US\csrss.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrss" /sc ONLOGON /tr "'C:\Windows\Branding\Basebrd\en-US\csrss.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrssc" /sc MINUTE /mo 13 /tr "'C:\Windows\Branding\Basebrd\en-US\csrss.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "taskhostt" /sc MINUTE /mo 7 /tr "'C:\Users\Default\Recent\taskhost.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "taskhost" /sc ONLOGON /tr "'C:\Users\Default\Recent\taskhost.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "taskhostt" /sc MINUTE /mo 9 /tr "'C:\Users\Default\Recent\taskhost.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwmd" /sc MINUTE /mo 8 /tr "'C:\Program Files\Windows Media Player\dwm.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwm" /sc ONLOGON /tr "'C:\Program Files\Windows Media Player\dwm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwmd" /sc MINUTE /mo 11 /tr "'C:\Program Files\Windows Media Player\dwm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "IdleI" /sc MINUTE /mo 6 /tr "'C:\Users\Public\Idle.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "Idle" /sc ONLOGON /tr "'C:\Users\Public\Idle.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "IdleI" /sc MINUTE /mo 5 /tr "'C:\Users\Public\Idle.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "servicess" /sc MINUTE /mo 7 /tr "'C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\services.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "services" /sc ONLOGON /tr "'C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\services.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "servicess" /sc MINUTE /mo 12 /tr "'C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\services.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvcs" /sc MINUTE /mo 5 /tr "'C:\Users\Admin\sppsvc.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvc" /sc ONLOGON /tr "'C:\Users\Admin\sppsvc.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvcs" /sc MINUTE /mo 11 /tr "'C:\Users\Admin\sppsvc.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwmd" /sc MINUTE /mo 12 /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\dwm.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwm" /sc ONLOGON /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\dwm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dwmd" /sc MINUTE /mo 11 /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\dwm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsml" /sc MINUTE /mo 9 /tr "'C:\Program Files\7-Zip\Lang\lsm.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsm" /sc ONLOGON /tr "'C:\Program Files\7-Zip\Lang\lsm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsml" /sc MINUTE /mo 12 /tr "'C:\Program Files\7-Zip\Lang\lsm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrssc" /sc MINUTE /mo 11 /tr "'C:\Windows\ShellNew\csrss.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrss" /sc ONLOGON /tr "'C:\Windows\ShellNew\csrss.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "csrssc" /sc MINUTE /mo 10 /tr "'C:\Windows\ShellNew\csrss.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvcs" /sc MINUTE /mo 8 /tr "'C:\Users\Default\My Documents\sppsvc.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvc" /sc ONLOGON /tr "'C:\Users\Default\My Documents\sppsvc.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "sppsvcs" /sc MINUTE /mo 8 /tr "'C:\Users\Default\My Documents\sppsvc.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsml" /sc MINUTE /mo 6 /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\lsm.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsm" /sc ONLOGON /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\lsm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "lsml" /sc MINUTE /mo 9 /tr "'C:\Recovery\3c6609c2-3a8b-11ef-9675-d685e2345d05\lsm.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "winlogonw" /sc MINUTE /mo 7 /tr "'C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\fr\winlogon.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "winlogon" /sc ONLOGON /tr "'C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\fr\winlogon.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "winlogonw" /sc MINUTE /mo 10 /tr "'C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\fr\winlogon.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 11 /tr "'C:\Windows\debug\WIA\dllhost.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dllhost" /sc ONLOGON /tr "'C:\Windows\debug\WIA\dllhost.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 10 /tr "'C:\Windows\debug\WIA\dllhost.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "SystemS" /sc MINUTE /mo 8 /tr "'C:\Windows\CSC\System.exe'" /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "System" /sc ONLOGON /tr "'C:\Windows\CSC\System.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
-
C:\Windows\system32\schtasks.exeschtasks.exe /create /tn "SystemS" /sc MINUTE /mo 6 /tr "'C:\Windows\CSC\System.exe'" /rl HIGHEST /f1⤵
- Process spawned unexpected child process
- Scheduled Task/Job: Scheduled Task
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Public\Idle.exeFilesize
2.3MB
MD511ec2263423a6c9c8ca33fe4c021e9a4
SHA1187934d7646cc1d33c923d1fbb0b385adbc411d1
SHA256e0a44f25632730e54db070a4508bdaf73621f4dc7f61987df2051d5d4b512ed7
SHA512d86b834a6554be6984222ddc926675e11df6d128841d51baba2f3b0e38ffcb08fdb7c01918a28c5db36c6c6c6799b8883a1131a9b41c5dc78a089c99151da4bf
-
memory/2368-8-0x0000000000580000-0x0000000000588000-memory.dmpFilesize
32KB
-
memory/2368-2-0x000007FEF5EB0000-0x000007FEF689C000-memory.dmpFilesize
9.9MB
-
memory/2368-5-0x0000000000D60000-0x0000000000DB6000-memory.dmpFilesize
344KB
-
memory/2368-6-0x00000000002F0000-0x0000000000302000-memory.dmpFilesize
72KB
-
memory/2368-9-0x0000000000BC0000-0x0000000000BC8000-memory.dmpFilesize
32KB
-
memory/2368-0-0x000007FEF5EB3000-0x000007FEF5EB4000-memory.dmpFilesize
4KB
-
memory/2368-1-0x00000000013B0000-0x0000000001602000-memory.dmpFilesize
2.3MB
-
memory/2368-47-0x000007FEF5EB0000-0x000007FEF689C000-memory.dmpFilesize
9.9MB
-
memory/2368-7-0x0000000000480000-0x000000000048E000-memory.dmpFilesize
56KB
-
memory/2368-4-0x0000000000BA0000-0x0000000000BB6000-memory.dmpFilesize
88KB
-
memory/2368-3-0x00000000002D0000-0x00000000002EC000-memory.dmpFilesize
112KB
-
memory/3000-46-0x0000000000030000-0x0000000000282000-memory.dmpFilesize
2.3MB
-
memory/3000-48-0x0000000000620000-0x0000000000632000-memory.dmpFilesize
72KB