General

  • Target

    06ff4ba1d0eec6c08d4b283d89f64f93_magniber_JC.exe

  • Size

    8.7MB

  • Sample

    230816-t73gwacb35

  • MD5

    06ff4ba1d0eec6c08d4b283d89f64f93

  • SHA1

    b5a6e9e2e5437fa03ec1f83fbce3675c9a1a5c50

  • SHA256

    1c6287821da0fb2fbc21f358cdc1aaed64d3ded4faf35749c0b38e9e37b6a017

  • SHA512

    c8f46a046c22433865aa2d4ecd66621624af82560f895e2daa0d82f46e1bcb238de0ba8fcb9a88558dc6e7778d447f0e7ccb6c15e7a3960b444c07e3b2bae6fe

  • SSDEEP

    196608:WBtayDqb6tgVatfRTYSrZtoagFwReADF6GnH+nX9cY1xyaD:WBtCetFtfBrLzDF62eNbQaD

Malware Config

Targets

    • Target

      06ff4ba1d0eec6c08d4b283d89f64f93_magniber_JC.exe

    • Size

      8.7MB

    • MD5

      06ff4ba1d0eec6c08d4b283d89f64f93

    • SHA1

      b5a6e9e2e5437fa03ec1f83fbce3675c9a1a5c50

    • SHA256

      1c6287821da0fb2fbc21f358cdc1aaed64d3ded4faf35749c0b38e9e37b6a017

    • SHA512

      c8f46a046c22433865aa2d4ecd66621624af82560f895e2daa0d82f46e1bcb238de0ba8fcb9a88558dc6e7778d447f0e7ccb6c15e7a3960b444c07e3b2bae6fe

    • SSDEEP

      196608:WBtayDqb6tgVatfRTYSrZtoagFwReADF6GnH+nX9cY1xyaD:WBtCetFtfBrLzDF62eNbQaD

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

System Information Discovery

1
T1082

Collection

Data from Local System

2
T1005

Tasks