General

  • Target

    2bf6834ce5765d30608ebb7078b8f73e2e80a5ea4e233683d145168f9143c317

  • Size

    103KB

  • Sample

    240324-xd6h8aeh57

  • MD5

    6c17d906687ffde9d566d799d8f9230c

  • SHA1

    914089c8083cdf929987f728e584ad79d222a68b

  • SHA256

    2bf6834ce5765d30608ebb7078b8f73e2e80a5ea4e233683d145168f9143c317

  • SHA512

    e34bb73baed15350515819d7fa0cbd3d6553746b12c6cf87a61993b7d53cd905eafc2ec6bb9bd1c057b39b68602a4cc118ddceb00c40b5b81b049d7a7c0d5f12

  • SSDEEP

    1536:iY9jw/dUT62rGdiUOWWrMu8i8N8tz8b8XtP8XtH8XtgUm2PmsZwGMaTZm:iY9CUT62/UOVMu8i8N898b8XN8X98XGl

Score
10/10

Malware Config

Targets

    • Target

      2bf6834ce5765d30608ebb7078b8f73e2e80a5ea4e233683d145168f9143c317

    • Size

      103KB

    • MD5

      6c17d906687ffde9d566d799d8f9230c

    • SHA1

      914089c8083cdf929987f728e584ad79d222a68b

    • SHA256

      2bf6834ce5765d30608ebb7078b8f73e2e80a5ea4e233683d145168f9143c317

    • SHA512

      e34bb73baed15350515819d7fa0cbd3d6553746b12c6cf87a61993b7d53cd905eafc2ec6bb9bd1c057b39b68602a4cc118ddceb00c40b5b81b049d7a7c0d5f12

    • SSDEEP

      1536:iY9jw/dUT62rGdiUOWWrMu8i8N8tz8b8XtP8XtH8XtgUm2PmsZwGMaTZm:iY9CUT62/UOVMu8i8N898b8XN8X98XGl

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks