General

  • Target

    HEUR-Trojan.Win32.Generic-aafc3915d064451788775d8779d037641b76c47fb0fa4a29f4cce250b33f3235

  • Size

    454KB

  • Sample

    240229-jsw2fabb62

  • MD5

    ebde6e0337f3239f806b8e6419722e87

  • SHA1

    95b69b0c17652e7aed72c307e587e90c1dba243d

  • SHA256

    aafc3915d064451788775d8779d037641b76c47fb0fa4a29f4cce250b33f3235

  • SHA512

    60b5b1cef2bf0825e6cba4a24e2cd9cb6b5d9c35bdc0739879835aa65f8c7719f6ca4d2fed395ce5fccd6359e9e59986d6f64249a7f92b6bab7e35c77ca5815e

  • SSDEEP

    6144:GY9C8QyNR9/ArE2O2LPhiZlgkm1EUHf01+3hWK4ECy83wscSstVZX8vgYldZ2XUE:GAf8g2O2LPi56EUHf0shru6

Score
10/10

Malware Config

Targets

    • Target

      HEUR-Trojan.Win32.Generic-aafc3915d064451788775d8779d037641b76c47fb0fa4a29f4cce250b33f3235

    • Size

      454KB

    • MD5

      ebde6e0337f3239f806b8e6419722e87

    • SHA1

      95b69b0c17652e7aed72c307e587e90c1dba243d

    • SHA256

      aafc3915d064451788775d8779d037641b76c47fb0fa4a29f4cce250b33f3235

    • SHA512

      60b5b1cef2bf0825e6cba4a24e2cd9cb6b5d9c35bdc0739879835aa65f8c7719f6ca4d2fed395ce5fccd6359e9e59986d6f64249a7f92b6bab7e35c77ca5815e

    • SSDEEP

      6144:GY9C8QyNR9/ArE2O2LPhiZlgkm1EUHf01+3hWK4ECy83wscSstVZX8vgYldZ2XUE:GAf8g2O2LPi56EUHf0shru6

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks