General

  • Target

    990acad7176719fc7ce6cf4d9337e7b0_magniber_JC.exe

  • Size

    8.7MB

  • Sample

    230825-sh6ybsda37

  • MD5

    990acad7176719fc7ce6cf4d9337e7b0

  • SHA1

    bef1810b9ddc039a096bfaba5f1b4392b3e47628

  • SHA256

    563b5f3c95294f3577426f39bf29606694215be6ff2e8ac3e0fa7906a3b50657

  • SHA512

    7343507ed1f4c931fe1e6b4e2abc1e7cbedf005d6f00cb3c495dede114de0200af056c29107122ce4e95fb67a49e303d168599c952a0413f8cd9f587bb6b7a4d

  • SSDEEP

    196608:cGxAdGiQw2QGAfpF0u1q8jntGJnSX/08iCgYj8x:cGOQw2QLpi8jnt2SXMBCXg

Malware Config

Targets

    • Target

      990acad7176719fc7ce6cf4d9337e7b0_magniber_JC.exe

    • Size

      8.7MB

    • MD5

      990acad7176719fc7ce6cf4d9337e7b0

    • SHA1

      bef1810b9ddc039a096bfaba5f1b4392b3e47628

    • SHA256

      563b5f3c95294f3577426f39bf29606694215be6ff2e8ac3e0fa7906a3b50657

    • SHA512

      7343507ed1f4c931fe1e6b4e2abc1e7cbedf005d6f00cb3c495dede114de0200af056c29107122ce4e95fb67a49e303d168599c952a0413f8cd9f587bb6b7a4d

    • SSDEEP

      196608:cGxAdGiQw2QGAfpF0u1q8jntGJnSX/08iCgYj8x:cGOQw2QLpi8jnt2SXMBCXg

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

System Information Discovery

1
T1082

Collection

Data from Local System

2
T1005

Tasks