Analysis

  • max time kernel
    150s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240704-en
  • resource tags

    arch:x64arch:x86image:win7-20240704-enlocale:en-usos:windows7-x64system
  • submitted
    05-07-2024 06:44

General

  • Target

    2024-07-05_01083cd7880b7ea6c91399679b0cfcfc_mafia.exe

  • Size

    1.9MB

  • MD5

    01083cd7880b7ea6c91399679b0cfcfc

  • SHA1

    64927394da2d2315c299fc5ed00c65e39fb3ad9c

  • SHA256

    a295e3f62797613cffbd72ad868835d7d654809cc805f24bcd1591cbf5ba86da

  • SHA512

    58e627768cd8d914eaa94b088f79190ac6741649b944df6dbe751c747b7eb02a028f27992b5195dad619bcac955de2e7ed2c91022ff6deded99fe61b9c1f947b

  • SSDEEP

    49152:eLHsnv2LhiwPMSSzX0K46WgInPBtD/kYsb:eLIOLhiNSST0GWzptDO

Score
1/10

Malware Config

Signatures

Processes

  • C:\Users\Admin\AppData\Local\Temp\2024-07-05_01083cd7880b7ea6c91399679b0cfcfc_mafia.exe
    "C:\Users\Admin\AppData\Local\Temp\2024-07-05_01083cd7880b7ea6c91399679b0cfcfc_mafia.exe"
    1⤵
      PID:2808

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • C:\Users\Admin\AppData\Roaming\Baidu\Baidushoujizhushou\Log\log_2808_2.log
      Filesize

      303B

      MD5

      fffd1fee83a7052dfd4bf58d15e222ed

      SHA1

      57b8599cd36cb0215af647b49ef0f93a13505f05

      SHA256

      4eecce73a1d546f50e6c69a3150895b31da2f908b6971cc107a04bbe9d3c340a

      SHA512

      be67bb83c89e56530eddac876856e4251a3a697bda509a165f32baf4672435a5e8d5d30a2f865e8dddd4f6bfa8f58e10a8e8cb918799998d456646dddafe2674

    • C:\Users\Admin\AppData\Roaming\Baidu\Baidushoujizhushou\Log\log_2808_3.log3.post
      Filesize

      532B

      MD5

      5cddb0aad8ddd36e636b02622845b406

      SHA1

      d0b0afa97e29c7039d11e4c4480558ac6273f6b7

      SHA256

      0f00ba083e8b798415bad50c7f2d2fcfd8b7e69bb79f792ec63dd3a0d10a298e

      SHA512

      ded888c6aa99430c3ad572be2e156d54f0065fd55ac59deeefa83e945bc4a947ca663260d250547aae164a5b50e537d55fdc697811fe549ef54303caca8e3250

    • memory/2808-0-0x0000000000100000-0x0000000000101000-memory.dmp
      Filesize

      4KB