General

  • Target

    70928f07076ca83678812570f1e9f05c.exe

  • Size

    11.3MB

  • Sample

    230930-twc3vafb93

  • MD5

    70928f07076ca83678812570f1e9f05c

  • SHA1

    9900429544963a60441ee1ef841eed87eeebf69a

  • SHA256

    4a20d88652a74ef776db2ace59a63815f3c446fb62f7d443145a97158ec19436

  • SHA512

    71cc7c856950194da15d7fab029d47ce697807973bf501a41aca7fe56df54f513cd63d47a098a7842262f7edc915b79748679468586bcbb88b0284b46d59329c

  • SSDEEP

    49152:fRBZj7amA9VSLGmJH77dPh89WU4OYDVD/ZnxMBStAkAqvlABXj6TKol4NWFg/Bbv:pW

Malware Config

Targets

    • Target

      70928f07076ca83678812570f1e9f05c.exe

    • Size

      11.3MB

    • MD5

      70928f07076ca83678812570f1e9f05c

    • SHA1

      9900429544963a60441ee1ef841eed87eeebf69a

    • SHA256

      4a20d88652a74ef776db2ace59a63815f3c446fb62f7d443145a97158ec19436

    • SHA512

      71cc7c856950194da15d7fab029d47ce697807973bf501a41aca7fe56df54f513cd63d47a098a7842262f7edc915b79748679468586bcbb88b0284b46d59329c

    • SSDEEP

      49152:fRBZj7amA9VSLGmJH77dPh89WU4OYDVD/ZnxMBStAkAqvlABXj6TKol4NWFg/Bbv:pW

    • Shurk

      Shurk is an infostealer, written in C++ which appeared in 2021.

    • Shurk Stealer payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Tasks