General

  • Target

    IoFLauncher.exe

  • Size

    11.6MB

  • Sample

    230828-hc7mkaae51

  • MD5

    124c2c589d0ba7dbc966123b3621ac5f

  • SHA1

    b15a3bc0ec613d3b7fd72125575c8b031d663bba

  • SHA256

    cebf8134aee3762147bed405c5e600631325e635b50d523ca913366dfa1afb7f

  • SHA512

    1752480298484c6c30f053e0791c8ad5bb913eaef082d46bfe085ff8bf5c1aa34fbae5b20fc0ac561ba0297a1017b6fa35dc93b1a5fce8641b3ea8d733ae6981

  • SSDEEP

    49152:tW125jirp0UyuMdH8offDzJzv8TxXF3ru66taoWRyswvmuT3ZaQYMiL4VYikt+6r:IU

Malware Config

Targets

    • Target

      IoFLauncher.exe

    • Size

      11.6MB

    • MD5

      124c2c589d0ba7dbc966123b3621ac5f

    • SHA1

      b15a3bc0ec613d3b7fd72125575c8b031d663bba

    • SHA256

      cebf8134aee3762147bed405c5e600631325e635b50d523ca913366dfa1afb7f

    • SHA512

      1752480298484c6c30f053e0791c8ad5bb913eaef082d46bfe085ff8bf5c1aa34fbae5b20fc0ac561ba0297a1017b6fa35dc93b1a5fce8641b3ea8d733ae6981

    • SSDEEP

      49152:tW125jirp0UyuMdH8offDzJzv8TxXF3ru66taoWRyswvmuT3ZaQYMiL4VYikt+6r:IU

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Tasks