Resubmissions

23-07-2023 20:32

230723-zbfk5ahb4z 10

General

  • Target

    AkebiPrivate.exe

  • Size

    7.8MB

  • Sample

    230723-zbfk5ahb4z

  • MD5

    397a2465056330bcbfe99dbfc5e1b844

  • SHA1

    5445d768d1d29c649add2cbe89b22462543fe03a

  • SHA256

    240c73bd79b521aa5cec91153917929082b969d37387f82554636c16f0ec5e26

  • SHA512

    30aafbbd19f53adfcb5078109b550a3d105b19efe14075a6dabefeea7b6314e55b78c08a64c3d658369eec44eba1e4d97c6b1bfa7523bf11a3f45abc38467e28

  • SSDEEP

    196608:PBZS6ykGjALAZRvMDfFnLTuref1hh/TPTS4nzsszTR7Ap:prygLAZknLTuref1hh/bTS4nzsszTRsp

Malware Config

Targets

    • Target

      AkebiPrivate.exe

    • Size

      7.8MB

    • MD5

      397a2465056330bcbfe99dbfc5e1b844

    • SHA1

      5445d768d1d29c649add2cbe89b22462543fe03a

    • SHA256

      240c73bd79b521aa5cec91153917929082b969d37387f82554636c16f0ec5e26

    • SHA512

      30aafbbd19f53adfcb5078109b550a3d105b19efe14075a6dabefeea7b6314e55b78c08a64c3d658369eec44eba1e4d97c6b1bfa7523bf11a3f45abc38467e28

    • SSDEEP

      196608:PBZS6ykGjALAZRvMDfFnLTuref1hh/TPTS4nzsszTR7Ap:prygLAZknLTuref1hh/bTS4nzsszTRsp

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Collection

Data from Local System

2
T1005

Tasks