General

  • Target

    ec602e5151e622f2f47d79575dc42aacf84681c7f4f901b146a5edb85507f788

  • Size

    4.3MB

  • Sample

    240410-r5raqabf84

  • MD5

    1fecb6eb98e8ee72bb5f006dd79c6f2f

  • SHA1

    be839bfca14bf92aed92083fd118afd1c7919f96

  • SHA256

    ec602e5151e622f2f47d79575dc42aacf84681c7f4f901b146a5edb85507f788

  • SHA512

    c459cbba1af2967bee875cf2820148ae3729182d7faeb3224418818d96e6ea18fa9e9f61fb82c34e931ecf630339d4d4e9e1da1a57668fd8c85100bcf7dac036

  • SSDEEP

    98304:Jr5Pi396Hjee/ATcUEuclRuPUSp6pPsklZnhNCv8Q6H6cI/nR:Jr509Gqe/AIUEuclR0USgpPsklZnev84

Malware Config

Extracted

Family

nullmixer

C2

http://estrix.xyz/

Targets

    • Target

      ec602e5151e622f2f47d79575dc42aacf84681c7f4f901b146a5edb85507f788

    • Size

      4.3MB

    • MD5

      1fecb6eb98e8ee72bb5f006dd79c6f2f

    • SHA1

      be839bfca14bf92aed92083fd118afd1c7919f96

    • SHA256

      ec602e5151e622f2f47d79575dc42aacf84681c7f4f901b146a5edb85507f788

    • SHA512

      c459cbba1af2967bee875cf2820148ae3729182d7faeb3224418818d96e6ea18fa9e9f61fb82c34e931ecf630339d4d4e9e1da1a57668fd8c85100bcf7dac036

    • SSDEEP

      98304:Jr5Pi396Hjee/ATcUEuclRuPUSp6pPsklZnhNCv8Q6H6cI/nR:Jr509Gqe/AIUEuclR0USgpPsklZnev84

    • NullMixer

      NullMixer is a malware dropper leading to an infection chain of a wide variety of malware families.

    • ASPack v2.12-2.42

      Detects executables packed with ASPack v2.12-2.42

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Target

      setup_installer.exe

    • Size

      4.3MB

    • MD5

      5de2818ced29a1fedb9b24c1044ebd45

    • SHA1

      c4ba9e1456ae58f25ae8d0d63cf192aa2a8bb506

    • SHA256

      6a9a3047c827fcd99d8a97668337ca2d7af78b3b634e73e2461e8429e264c7e2

    • SHA512

      9e43a56af0c2a3deac9528b1805f9ee00958c018194b4297149f3bd34fa9be81a133c6592a961d9f4989cbeb5436d2b764e8fc3f7a4410be676a40faf46a2656

    • SSDEEP

      98304:xwCvLUBsgDAFcgEYkZPc8PA34Ztu6dh1VwE3soCHeEGdnmX:xNLUCgDAOgEYkZPDAIZtu6dh1p3sveEb

    • NullMixer

      NullMixer is a malware dropper leading to an infection chain of a wide variety of malware families.

    • ASPack v2.12-2.42

      Detects executables packed with ASPack v2.12-2.42

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

2
T1012

System Information Discovery

4
T1082

Tasks