General

  • Target

    108dd8675ad26778748b563a1f590fef6f9875d484002e3d48adb7268358263d

  • Size

    7.7MB

  • Sample

    230810-vfsn2afd47

  • MD5

    78bc9c35531a7e1a31af3bdff4083df6

  • SHA1

    a679051cff10c802a126c25c42f12fefac857a31

  • SHA256

    108dd8675ad26778748b563a1f590fef6f9875d484002e3d48adb7268358263d

  • SHA512

    2a41f758b0da999e3d2afbe4c7f0f5b4d675dc643f866d4947b9570c9b8ccd6bc3ebf44a67c82633ae9992404c1e9a9ba0956712a451446a9e8ddd6fcc1ef526

  • SSDEEP

    196608:SdrOnwUbN9pdNqVWEwLnN+HDc/Up7sSpoVmPYYfW/:SVRUb5dN65ON+AMWS6VmlW/

Malware Config

Targets

    • Target

      108dd8675ad26778748b563a1f590fef6f9875d484002e3d48adb7268358263d

    • Size

      7.7MB

    • MD5

      78bc9c35531a7e1a31af3bdff4083df6

    • SHA1

      a679051cff10c802a126c25c42f12fefac857a31

    • SHA256

      108dd8675ad26778748b563a1f590fef6f9875d484002e3d48adb7268358263d

    • SHA512

      2a41f758b0da999e3d2afbe4c7f0f5b4d675dc643f866d4947b9570c9b8ccd6bc3ebf44a67c82633ae9992404c1e9a9ba0956712a451446a9e8ddd6fcc1ef526

    • SSDEEP

      196608:SdrOnwUbN9pdNqVWEwLnN+HDc/Up7sSpoVmPYYfW/:SVRUb5dN65ON+AMWS6VmlW/

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Downloads MZ/PE file

    • Executes dropped EXE

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

System Information Discovery

1
T1082

Collection

Data from Local System

2
T1005

Tasks