General

  • Target

    acfb70e071355b050c3d3ad4e99c760b922d0ce85930b1d92403186c540d7d73

  • Size

    571KB

  • Sample

    220502-st3eaaaedr

  • MD5

    3b162f81c028a43f6b00e69043fdb295

  • SHA1

    9f057b9561b55d8b81db0b4de8239791ea043349

  • SHA256

    acfb70e071355b050c3d3ad4e99c760b922d0ce85930b1d92403186c540d7d73

  • SHA512

    029430b4f59b4be230b91615b2439f4e51233d1d9ac3c3bcff61982cbd98ffead3d089d8c093427ee9b7b6a3442152611e335aa704b8f3caa54e995bb00cdea9

Malware Config

Targets

    • Target

      acfb70e071355b050c3d3ad4e99c760b922d0ce85930b1d92403186c540d7d73

    • Size

      571KB

    • MD5

      3b162f81c028a43f6b00e69043fdb295

    • SHA1

      9f057b9561b55d8b81db0b4de8239791ea043349

    • SHA256

      acfb70e071355b050c3d3ad4e99c760b922d0ce85930b1d92403186c540d7d73

    • SHA512

      029430b4f59b4be230b91615b2439f4e51233d1d9ac3c3bcff61982cbd98ffead3d089d8c093427ee9b7b6a3442152611e335aa704b8f3caa54e995bb00cdea9

    • Taurus Stealer

      Taurus is an infostealer first seen in June 2020.

    • Taurus Stealer Payload

    • Accesses 2FA software files, possible credential harvesting

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v6

Credential Access

Credentials in Files

1
T1081

Collection

Data from Local System

1
T1005

Tasks