Overview
overview
10Static
static
3stage3.zip
windows10-2004-x64
10BugSplat.dll
windows10-2004-x64
3Drieb.ba
windows10-2004-x64
3Drouncloobthoub.odo
windows10-2004-x64
3MonitoData.exe
windows10-2004-x64
10ThreadCore.dll
windows10-2004-x64
3ios_manager.dll
windows10-2004-x64
3itunes_manager.dll
windows10-2004-x64
3libcurl.dll
windows10-2004-x64
3msvcp140.dll
windows10-2004-x64
3ts_base.dll
windows10-2004-x64
3ts_client.dll
windows10-2004-x64
3ts_sqlite3.dll
windows10-2004-x64
3vcruntime140.dll
windows10-2004-x64
3Analysis
-
max time kernel
103s -
max time network
132s -
platform
windows10-2004_x64 -
resource
win10v2004-20250502-en -
resource tags
arch:x64arch:x86image:win10v2004-20250502-enlocale:en-usos:windows10-2004-x64system -
submitted
21/05/2025, 00:13
Static task
static1
Behavioral task
behavioral1
Sample
stage3.zip
Resource
win10v2004-20250502-en
Behavioral task
behavioral2
Sample
BugSplat.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral3
Sample
Drieb.ba
Resource
win10v2004-20250502-en
Behavioral task
behavioral4
Sample
Drouncloobthoub.odo
Resource
win10v2004-20250502-en
Behavioral task
behavioral5
Sample
MonitoData.exe
Resource
win10v2004-20250502-en
Behavioral task
behavioral6
Sample
ThreadCore.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral7
Sample
ios_manager.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral8
Sample
itunes_manager.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral9
Sample
libcurl.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral10
Sample
msvcp140.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral11
Sample
ts_base.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral12
Sample
ts_client.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral13
Sample
ts_sqlite3.dll
Resource
win10v2004-20250502-en
Behavioral task
behavioral14
Sample
vcruntime140.dll
Resource
win10v2004-20250502-en
General
-
Target
vcruntime140.dll
-
Size
81KB
-
MD5
e51018e4985943c51ff91471f8906504
-
SHA1
5899aaccdb692dbdffdaa35436c47d17c130cfd0
-
SHA256
ff9c1123cff493a8f5eacb91115611b6c1c808b30c82af9b6f388c0ef1f6b46d
-
SHA512
2fe5ddad2100aeaea35398384a440ba0be169ef429f7e0b69687bc0f8865df41bc93fc80d3a8f0ddd9df54fc2f2d76b1056a1d1962d37432704c818128ffbd74
-
SSDEEP
1536:lmGzxv5o1xSEIURDbnZ/dvC5cpnHXCh5cecbvo9J/Z0:lp5o1YEIU9bnZ/A5y3Jecbvo9
Malware Config
Signatures
-
Program crash 1 IoCs
pid pid_target Process procid_target 4104 3848 WerFault.exe 85 -
System Location Discovery: System Language Discovery 1 TTPs 1 IoCs
Attempt gather information about the system language of a victim in order to infer the geographical location of that host.
description ioc Process Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\NLS\Language rundll32.exe -
Suspicious use of WriteProcessMemory 3 IoCs
description pid Process procid_target PID 2212 wrote to memory of 3848 2212 rundll32.exe 85 PID 2212 wrote to memory of 3848 2212 rundll32.exe 85 PID 2212 wrote to memory of 3848 2212 rundll32.exe 85
Processes
-
C:\Windows\system32\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\vcruntime140.dll,#11⤵
- Suspicious use of WriteProcessMemory
PID:2212 -
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\vcruntime140.dll,#12⤵
- System Location Discovery: System Language Discovery
PID:3848 -
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -u -p 3848 -s 6003⤵
- Program crash
PID:4104
-
-
-
C:\Windows\SysWOW64\WerFault.exeC:\Windows\SysWOW64\WerFault.exe -pss -s 408 -p 3848 -ip 38481⤵PID:3812