General

  • Target

    45ecf24b2acb7608dd74e2b408ab182f3b3632e780ffd414ab6dc30f328e08f6

  • Size

    102KB

  • Sample

    240328-yd535afe53

  • MD5

    4dc86e0363972bd701ec2b95a083fc55

  • SHA1

    780a0a77ab9e685750423934f1cceaadfffac614

  • SHA256

    45ecf24b2acb7608dd74e2b408ab182f3b3632e780ffd414ab6dc30f328e08f6

  • SHA512

    df40f443afa82a67cd5aecc26a2a894f3a9eb06abb0d8f06595900d3d2be46e690aa64f8de4eeafb4e8991e3b50f8fcd40b91d07ee3af9a9d2427fe6b4ce8605

  • SSDEEP

    1536:iY9jw/dUT62rGdiUOWWrMu8i8N8tz8b8XtP8XtH8XtgUm2PmsZwGMTK2:iY9CUT62/UOVMu8i8N898b8XN8X98XGT

Score
10/10

Malware Config

Targets

    • Target

      45ecf24b2acb7608dd74e2b408ab182f3b3632e780ffd414ab6dc30f328e08f6

    • Size

      102KB

    • MD5

      4dc86e0363972bd701ec2b95a083fc55

    • SHA1

      780a0a77ab9e685750423934f1cceaadfffac614

    • SHA256

      45ecf24b2acb7608dd74e2b408ab182f3b3632e780ffd414ab6dc30f328e08f6

    • SHA512

      df40f443afa82a67cd5aecc26a2a894f3a9eb06abb0d8f06595900d3d2be46e690aa64f8de4eeafb4e8991e3b50f8fcd40b91d07ee3af9a9d2427fe6b4ce8605

    • SSDEEP

      1536:iY9jw/dUT62rGdiUOWWrMu8i8N8tz8b8XtP8XtH8XtgUm2PmsZwGMTK2:iY9CUT62/UOVMu8i8N898b8XN8X98XGT

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks