General

  • Target

    Update.js

  • Size

    439KB

  • Sample

    240425-s2944acb68

  • MD5

    7125357715f688577910416555a1997a

  • SHA1

    494f4befa879ac5174ddfd2c0f0ff0c711251eb8

  • SHA256

    8fe424869272394512941904c4b1ba7039ac2a514acb9861e613f5e85222d9a7

  • SHA512

    05cc9f9e6046866090395624cee673439ec4cd896fd3c24010a209ab54789ab9e93b45907b403aeb04fd7d8a50cbe35eed2e9c80847cd1f2cc51785ad4a4f294

  • SSDEEP

    1536:TBEEBEEBEPZBEwBEkBEGZBEiZBEGZBEGZBEG5+BEVBYBEG+BEVB/+BEBBEG+BEVq:6

Malware Config

Extracted

Language
ps1
Deobfuscated
URLs
ps1.dropper

http://77.221.151.31/a/z.png

Extracted

Language
ps1
Deobfuscated
URLs
ps1.dropper

http://77.221.151.31/a/s.png

Extracted

Family

bitrat

Version

1.38

C2

77.221.151.31:4444

Attributes
  • communication_password

    7b13ff385b95cf25d53088d6b7c5d890

  • tor_process

    tor

Targets

    • Target

      Update.js

    • Size

      439KB

    • MD5

      7125357715f688577910416555a1997a

    • SHA1

      494f4befa879ac5174ddfd2c0f0ff0c711251eb8

    • SHA256

      8fe424869272394512941904c4b1ba7039ac2a514acb9861e613f5e85222d9a7

    • SHA512

      05cc9f9e6046866090395624cee673439ec4cd896fd3c24010a209ab54789ab9e93b45907b403aeb04fd7d8a50cbe35eed2e9c80847cd1f2cc51785ad4a4f294

    • SSDEEP

      1536:TBEEBEEBEPZBEwBEkBEGZBEiZBEGZBEGZBEG5+BEVBYBEG+BEVB/+BEBBEG+BEVq:6

    • BitRAT

      BitRAT is a remote access tool written in C++ and uses leaked source code from other families.

    • Blocklisted process makes network request

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Adds Run key to start application

    • Suspicious use of NtSetInformationThreadHideFromDebugger

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Discovery

System Information Discovery

1
T1082

Tasks