General

  • Target

    6f99b05458d778055d7493a9490adadd

  • Size

    12KB

  • Sample

    240122-q7qarsgge7

  • MD5

    6f99b05458d778055d7493a9490adadd

  • SHA1

    5671a418317d8a13b996d2054efd28cb599b399c

  • SHA256

    cdac5edd109e6e7e681d08dc691a163a20184f53c3c511e2bef622a6c66b60fd

  • SHA512

    35dced20279fb7f8a7b03120a527fbd8dfd26cef37272cd74aec3e6209342739181f77879236df2cf77de74b87c988677de4bfeb8cd5ebdd2f422e33b40c0c34

  • SSDEEP

    384:6K+dKfzQHxFxRmyja4QhiP7UlY/pjKkFlplYyfQ:v+dAURFxna4QAPQlYgkFlplYyfQ

Score
10/10

Malware Config

Targets

    • Target

      6f99b05458d778055d7493a9490adadd

    • Size

      12KB

    • MD5

      6f99b05458d778055d7493a9490adadd

    • SHA1

      5671a418317d8a13b996d2054efd28cb599b399c

    • SHA256

      cdac5edd109e6e7e681d08dc691a163a20184f53c3c511e2bef622a6c66b60fd

    • SHA512

      35dced20279fb7f8a7b03120a527fbd8dfd26cef37272cd74aec3e6209342739181f77879236df2cf77de74b87c988677de4bfeb8cd5ebdd2f422e33b40c0c34

    • SSDEEP

      384:6K+dKfzQHxFxRmyja4QhiP7UlY/pjKkFlplYyfQ:v+dAURFxna4QAPQlYgkFlplYyfQ

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks