Windows
Analysis Report
f492136216_mpengine_dll
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Found strings related to Crypto-Mining
Maps a DLL or memory area into another process
Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)
Detected non-DNS traffic on DNS port
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
One or more processes crash
PE file contains executable resources (Code or Archives)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Stores large binary data to the registry
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w11x64_office
loaddll64.exe (PID: 7076 cmdline:
loaddll64. exe "C:\Us ers\user\D esktop\f49 2136216_mp engine_dll .dll" MD5: 763455F9DCB24DFEECC2B9D9F8D46D52) conhost.exe (PID: 3728 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 9698384842DA735D80D278A427A229AB) cmd.exe (PID: 376 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\f49 2136216_mp engine_dll .dll",#1 MD5: 428CEC6B0034E0F183EB5BAE887BE480) rundll32.exe (PID: 3548 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",#1 MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 4972 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 3 548 -s 452 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 6028 cmdline:
rundll32.e xe C:\User s\user\Des ktop\f4921 36216_mpen gine_dll.d ll,FreeSig Files MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 2720 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 028 -s 436 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 3296 cmdline:
rundll32.e xe C:\User s\user\Des ktop\f4921 36216_mpen gine_dll.d ll,GetSigF iles MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 6340 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 3 296 -s 440 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 6992 cmdline:
rundll32.e xe C:\User s\user\Des ktop\f4921 36216_mpen gine_dll.d ll,MpBootS trap MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 6376 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",FreeS igFiles MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 6128 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 376 -s 436 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 4112 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",GetSi gFiles MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 816 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 4 112 -s 436 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 1972 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpBoo tStrap MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 5924 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",rsign al MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 3452 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",__rsi gnal MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 1144 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerWrit e MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 6216 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerSetS ize MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 1176 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 216 -s 444 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 7044 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerRead MD5: C87FA6FC1D294962EABE44509FE1921C) WerFault.exe (PID: 6264 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 7 044 -s 444 MD5: 5A849C27C4796C1A7C22C572D8EAF95D) rundll32.exe (PID: 3360 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerOpen Object MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 1828 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerOpen MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 6960 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerGetN ext MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 1252 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerFree ObjectInfo MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 6548 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerDele te MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 2220 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerComm it MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 4052 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerClos eObject MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 2244 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerClos e MD5: C87FA6FC1D294962EABE44509FE1921C) rundll32.exe (PID: 1136 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\f492 136216_mpe ngine_dll. dll",MpCon tainerAnal yze MD5: C87FA6FC1D294962EABE44509FE1921C)
EXCEL.EXE (PID: 6056 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Root\ Office16\E XCEL.EXE" "C:\Users\ user\Deskt op\LSBIHQF DVT.xlsx" MD5: F9F7B6C42211B06E7AC3E4B60AA8FB77)
POWERPNT.EXE (PID: 5708 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\root\ Office16\P OWERPNT.EX E" MD5: 60E58060E6B6C8E4918851AC6A9DD340) ai.exe (PID: 3672 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\root\ vfs\Progra mFilesComm onX64\Micr osoft Shar ed\Office1 6\AI\ai.ex e" "E98E54 CA-9ED0-4A 3C-82B1-43 5F18C73083 " "E93A25E 5-42BA-4E8 5-BCDE-304 43779E8E4" "5708" "C :\Program Files\Micr osoft Offi ce\root\Of fice16\POW ERPNT.EXE" "PowerPoi ntCombined FloatieLre Online.onn x" MD5: 0ED71A2D20424DC7942E810F359DA066)
WebViewHost.exe (PID: 7048 cmdline:
"C:\Progra m Files\Wi ndowsApps\ Microsoft. MicrosoftO fficeHub_1 8.2411.116 3.0_x64__8 wekyb3d8bb we\WebView Host.exe" MD5: 737C3D5A23C7B81B3969762D79E817BD) msedgewebview2.exe (PID: 1444 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --embedd ed-browser -webview=1 --webview -exe-name= WebViewHos t.exe --we bview-exe- version=18 .2411.1163 .0 --user- data-dir=" C:\Users\u ser\AppDat a\Local\Pa ckages\Mic rosoft.Mic rosoftOffi ceHub_8wek yb3d8bbwe\ LocalState \EBWebView " --noerrd ialogs --e mbedded-br owser-webv iew-dpi-aw areness=2 --enable-f eatures=ms SingleSign OnOSForPri maryAccoun tIsShared --mojo-nam ed-platfor m-channel- pipe=7048. 1824.92305 7819869824 4367 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 7088 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=c rashpad-ha ndler --us er-data-di r=C:\Users \user\AppD ata\Local\ Packages\M icrosoft.M icrosoftOf ficeHub_8w ekyb3d8bbw e\LocalSta te\EBWebVi ew /prefet ch:7 --mon itor-self- annotation =ptype=cra shpad-hand ler --data base=C:\Us ers\user\A ppData\Loc al\Package s\Microsof t.Microsof tOfficeHub _8wekyb3d8 bbwe\Local State\EBWe bView\Cras hpad --ann otation=Is OfficialBu ild=1 --an notation=c hannel= -- annotation =chromium- version=10 0.0.4896.7 5 "--annot ation=exe= C:\Program Files (x8 6)\Microso ft\EdgeWeb View\Appli cation\100 .0.1185.36 \msedgeweb view2.exe" --annotat ion=plat=W in64 "--an notation=p rod=Edge W ebView2" - -annotatio n=ver=100. 0.1185.36 --initial- client-dat a=0x138,0x 13c,0x140, 0x114,0x14 8,0x7ff9a2 d6d840,0x7 ff9a2d6d85 0,0x7ff9a2 d6d860 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 5876 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=g pu-process --noerrdi alogs --us er-data-di r="C:\User s\user\App Data\Local \Packages\ Microsoft. MicrosoftO fficeHub_8 wekyb3d8bb we\LocalSt ate\EBWebV iew" --web view-exe-n ame=WebVie wHost.exe --webview- exe-versio n=18.2411. 1163.0 --e mbedded-br owser-webv iew=1 --em bedded-bro wser-webvi ew-dpi-awa reness=2 - -gpu-prefe rences=UAA AAAAAAADgA AAYAAAAAAA AAAAAAAAAA ABgAAAAAAA wAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AAEgAAAAAA AAASAAAAAA AAAAYAAAAA gAAABAAAAA AAAAAGAAAA AAAAAAQAAA AAAAAAAAAA AAOAAAAEAA AAAAAAAABA AAADgAAAAg AAAAAAAAAC AAAAAAAAAA = --mojo-p latform-ch annel-hand le=1904 -- field-tria l-handle=2 000,i,1152 6659406399 15510,1704 2987104756 587829,131 072 --enab le-feature s=msSingle SignOnOSFo rPrimaryAc countIsSha red /prefe tch:2 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 6068 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=u tility --u tility-sub -type=netw ork.mojom. NetworkSer vice --lan g=en-US -- service-sa ndbox-type =none --no errdialogs --user-da ta-dir="C: \Users\use r\AppData\ Local\Pack ages\Micro soft.Micro softOffice Hub_8wekyb 3d8bbwe\Lo calState\E BWebView" --webview- exe-name=W ebViewHost .exe --web view-exe-v ersion=18. 2411.1163. 0 --embedd ed-browser -webview=1 --embedde d-browser- webview-dp i-awarenes s=2 --mojo -platform- channel-ha ndle=2092 --field-tr ial-handle =2000,i,11 5266594063 9915510,17 0429871047 56587829,1 31072 --en able-featu res=msSing leSignOnOS ForPrimary AccountIsS hared /pre fetch:3 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 848 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=u tility --u tility-sub -type=stor age.mojom. StorageSer vice --lan g=en-US -- service-sa ndbox-type =utility - -noerrdial ogs --user -data-dir= "C:\Users\ user\AppDa ta\Local\P ackages\Mi crosoft.Mi crosoftOff iceHub_8we kyb3d8bbwe \LocalStat e\EBWebVie w" --webvi ew-exe-nam e=WebViewH ost.exe -- webview-ex e-version= 18.2411.11 63.0 --emb edded-brow ser-webvie w=1 --embe dded-brows er-webview -dpi-aware ness=2 --m ojo-platfo rm-channel -handle=23 96 --field -trial-han dle=2000,i ,115266594 0639915510 ,170429871 0475658782 9,131072 - -enable-fe atures=msS ingleSignO nOSForPrim aryAccount IsShared / prefetch:8 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 6336 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=r enderer -- noerrdialo gs --user- data-dir=" C:\Users\u ser\AppDat a\Local\Pa ckages\Mic rosoft.Mic rosoftOffi ceHub_8wek yb3d8bbwe\ LocalState \EBWebView " --webvie w-exe-name =WebViewHo st.exe --w ebview-exe -version=1 8.2411.116 3.0 --embe dded-brows er-webview =1 --embed ded-browse r-webview- dpi-awaren ess=2 --di sable-clie nt-side-ph ishing-det ection --d isplay-cap ture-permi ssions-pol icy-allowe d --js-fla gs="--harm ony-weak-r efs-with-c leanup-som e --expose -gc" --lan g=en-US -- device-sca le-factor= 1 --num-ra ster-threa ds=2 --ena ble-main-f rame-befor e-activati on --rende rer-client -id=5 --la unch-time- ticks=3993 088734 --m ojo-platfo rm-channel -handle=31 96 --field -trial-han dle=2000,i ,115266594 0639915510 ,170429871 0475658782 9,131072 - -enable-fe atures=msS ingleSignO nOSForPrim aryAccount IsShared / prefetch:1 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 9128 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=g pu-process --disable -gpu-sandb ox --use-g l=disabled --gpu-ven dor-id=329 02 --gpu-d evice-id=3 2069 --gpu -sub-syste m-id=0 --g pu-revisio n=0 --gpu- driver-ver sion=10.0. 22621.3672 --noerrdi alogs --us er-data-di r="C:\User s\user\App Data\Local \Packages\ Microsoft. MicrosoftO fficeHub_8 wekyb3d8bb we\LocalSt ate\EBWebV iew" --web view-exe-n ame=WebVie wHost.exe --webview- exe-versio n=18.2411. 1163.0 --e mbedded-br owser-webv iew=1 --em bedded-bro wser-webvi ew-dpi-awa reness=2 - -gpu-prefe rences=UAA AAAAAAADoA AAYAAAAAAA AAAAAAAAAA ABgAAAAAAA wAAAAAAAAA AAAAAAAAQA AAAAAAAAAA AAAAAAAAAA AAEgAAAAAA AAASAAAAAA AAAAYAAAAA gAAABAAAAA AAAAAGAAAA AAAAAAQAAA AAAAAAAAAA AAOAAAAEAA AAAAAAAABA AAADgAAAAg AAAAAAAAAC AAAAAAAAAA = --mojo-p latform-ch annel-hand le=1796 -- field-tria l-handle=2 000,i,1152 6659406399 15510,1704 2987104756 587829,131 072 --enab le-feature s=msSingle SignOnOSFo rPrimaryAc countIsSha red /prefe tch:2 MD5: 7333249A2DA2F769900496F812DFBD57)
msedge.exe (PID: 6992 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA) msedge.exe (PID: 7344 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" --type= utility -- utility-su b-type=net work.mojom .NetworkSe rvice --la ng=en-US - -service-s andbox-typ e=none --m ojo-platfo rm-channel -handle=20 88 --field -trial-han dle=2176,i ,113910056 1183820370 4,44149655 7788928380 4,131072 / prefetch:3 MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA) identity_helper.exe (PID: 7692 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \100.0.118 5.36\ident ity_helper .exe" --ty pe=utility --utility -sub-type= winrt_app_ id.mojom.W inrtAppIdS ervice --l ang=en-US --service- sandbox-ty pe=none -- mojo-platf orm-channe l-handle=4 272 --fiel d-trial-ha ndle=2176, i,11391005 6118382037 04,4414965 5778892838 04,131072 /prefetch: 8 MD5: 799B8192198E431938AD498DA9EFE217) identity_helper.exe (PID: 7784 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \100.0.118 5.36\ident ity_helper .exe" --ty pe=utility --utility -sub-type= winrt_app_ id.mojom.W inrtAppIdS ervice --l ang=en-US --service- sandbox-ty pe=none -- mojo-platf orm-channe l-handle=4 272 --fiel d-trial-ha ndle=2176, i,11391005 6118382037 04,4414965 5778892838 04,131072 /prefetch: 8 MD5: 799B8192198E431938AD498DA9EFE217) msedge.exe (PID: 9000 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" --type= utility -- utility-su b-type=ent ity_extrac tion_servi ce.mojom.E xtractor - -lang=en-U S --servic e-sandbox- type=entit y_extracti on --mojo- platform-c hannel-han dle=5332 - -field-tri al-handle= 2176,i,113 9100561183 8203704,44 1496557788 9283804,13 1072 /pref etch:8 MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA)
- cleanup
⊘No configs have been found
⊘No yara matches
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Source: | Binary or memory string: | memstr_14b985f9-9 |
Bitcoin Miner |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |