Source: Process started | Author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements): Data: Command: net stop BMR Boot Service /y, CommandLine: net stop BMR Boot Service /y, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c ''C:\Users\user\Desktop\kill.bat' 'C:\Users\user\Desktop\cring.exe'', ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 6048, ProcessCommandLine: net stop BMR Boot Service /y, ProcessId: 6104 |
Source: cring.exe | Binary or memory string: OriginalFilename vs cring.exe |
Source: cring.exe, 00000000.00000002.324569603.0000000000F9C000.00000004.00000020.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs cring.exe |
Source: cring.exe, 00000000.00000002.324729946.0000000001340000.00000002.00000001.sdmp | Binary or memory string: originalfilename vs cring.exe |
Source: cring.exe, 00000000.00000002.324729946.0000000001340000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs cring.exe |
Source: cring.exe, 00000000.00000002.324691361.00000000012E0000.00000002.00000001.sdmp | Binary or memory string: System.OriginalFileName vs cring.exe |
Source: classification engine | Classification label: sus25.winEXE@28/3@0/0 |
Source: C:\Users\user\Desktop\cring.exe | File created: C:\Users\user\Desktop\kill.bat | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4552:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6052:120:WilError_01 |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\Desktop\kill.bat' 'C:\Users\user\Desktop\cring.exe'' |
Source: cring.exe | Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\cring.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\ac26e2af62f23e37e645b5e44068a025\mscorlib.ni.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "mspub.exe") |
Source: C:\Windows\System32\taskkill.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "mydesktopqos.exe") |
Source: C:\Windows\System32\taskkill.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "mydesktopservice.exe") |
Source: C:\Users\user\Desktop\cring.exe | File read: C:\Users\desktop.ini | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\cring.exe 'C:\Users\user\Desktop\cring.exe' | |
Source: unknown | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\Desktop\kill.bat' 'C:\Users\user\Desktop\cring.exe'' | |
Source: unknown | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: unknown | Process created: C:\Windows\System32\net.exe net stop BMR Boot Service /y | |
Source: unknown | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop BMR Boot Service /y | |
Source: unknown | Process created: C:\Windows\System32\net.exe net stop NetBackup BMR MTFTP Service /y | |
Source: unknown | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop NetBackup BMR MTFTP Service /y | |
Source: unknown | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY start= disabled | |
Source: unknown | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY$ECWDB2 start= disabled | |
Source: unknown | Process created: C:\Windows\System32\sc.exe sc config SQLWriter start= disabled | |
Source: unknown | Process created: C:\Windows\System32\sc.exe sc config SstpSvc start= disabled | |
Source: unknown | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mspub.exe /F | |
Source: unknown | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopqos.exe /F | |
Source: unknown | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopservice.exe /F | |
Source: C:\Users\user\Desktop\cring.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\Desktop\kill.bat' 'C:\Users\user\Desktop\cring.exe'' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\net.exe net stop BMR Boot Service /y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\net.exe net stop NetBackup BMR MTFTP Service /y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY$ECWDB2 start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLWriter start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SstpSvc start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mspub.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopqos.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopservice.exe /F | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop BMR Boot Service /y | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop NetBackup BMR MTFTP Service /y | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32 | Jump to behavior |
Source: cring.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR |
Source: cring.exe | Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT |
Source: cring.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: | Binary string: C:\Users\FuckCrowStrike\Desktop\NewCring\Crypt3r\obj\Release\cring.pdb source: cring.exe |
Source: initial sample | Static PE information: 0xA069F415 [Wed Apr 14 06:52:05 2055 UTC] |
Source: unknown | Process created: C:\Windows\System32\net.exe net stop BMR Boot Service /y |
Source: unknown | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY start= disabled |
Source: C:\Users\user\Desktop\cring.exe | Registry key monitored for changes: HKEY_CURRENT_USER_Classes | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | File opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe TID: 6640 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: sc.exe, 00000008.00000002.330354414.0000025ACD650000.00000002.00000001.sdmp, sc.exe, 00000009.00000002.331433462.0000026F021C0000.00000002.00000001.sdmp, sc.exe, 0000000A.00000002.332589167.0000020625470000.00000002.00000001.sdmp | Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: sc.exe, 00000008.00000002.330354414.0000025ACD650000.00000002.00000001.sdmp, sc.exe, 00000009.00000002.331433462.0000026F021C0000.00000002.00000001.sdmp, sc.exe, 0000000A.00000002.332589167.0000020625470000.00000002.00000001.sdmp | Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: sc.exe, 00000008.00000002.330354414.0000025ACD650000.00000002.00000001.sdmp, sc.exe, 00000009.00000002.331433462.0000026F021C0000.00000002.00000001.sdmp, sc.exe, 0000000A.00000002.332589167.0000020625470000.00000002.00000001.sdmp | Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: sc.exe, 00000008.00000002.330354414.0000025ACD650000.00000002.00000001.sdmp, sc.exe, 00000009.00000002.331433462.0000026F021C0000.00000002.00000001.sdmp, sc.exe, 0000000A.00000002.332589167.0000020625470000.00000002.00000001.sdmp | Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Windows\System32\taskkill.exe | Process token adjusted: Debug | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Process token adjusted: Debug | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Process token adjusted: Debug | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Memory allocated: page read and write | page guard | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Users\user\Desktop\kill.bat' 'C:\Users\user\Desktop\cring.exe'' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\net.exe net stop BMR Boot Service /y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\net.exe net stop NetBackup BMR MTFTP Service /y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLTELEMETRY$ECWDB2 start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SQLWriter start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\sc.exe sc config SstpSvc start= disabled | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mspub.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopqos.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopservice.exe /F | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop BMR Boot Service /y | Jump to behavior |
Source: C:\Windows\System32\net.exe | Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop NetBackup BMR MTFTP Service /y | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mspub.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopqos.exe /F | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /IM mydesktopservice.exe /F | Jump to behavior |
Source: C:\Users\user\Desktop\cring.exe | Queries volume information: C:\Users\user\Desktop\cring.exe VolumeInformation | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.