General

  • Target

    62990bd81297a42bf5348c15a196e488a531420d12869392c5bd0724ca997c9d.exe

  • Size

    439KB

  • Sample

    240514-tsb2daee24

  • MD5

    1885cacfae37edb28b438588771fb03f

  • SHA1

    b8b86b6ddc681a9333628f344875d9d33fee7185

  • SHA256

    62990bd81297a42bf5348c15a196e488a531420d12869392c5bd0724ca997c9d

  • SHA512

    afc2b931689f21c1b7770735f2292c2fa667b86123354d8409d264118e1908f22dddd58fc17545e9feaae786c2414133923c2170be879ff502398f87c556d57e

  • SSDEEP

    6144:NZi9pP2JNMv8P4WyKNh6xzRnM3VVYijO9Wi7XMJRAc3ewc5n5:NZibPoKv6fNhEFMDBMWY3cu/5

Score
10/10

Malware Config

Targets

    • Target

      62990bd81297a42bf5348c15a196e488a531420d12869392c5bd0724ca997c9d.exe

    • Size

      439KB

    • MD5

      1885cacfae37edb28b438588771fb03f

    • SHA1

      b8b86b6ddc681a9333628f344875d9d33fee7185

    • SHA256

      62990bd81297a42bf5348c15a196e488a531420d12869392c5bd0724ca997c9d

    • SHA512

      afc2b931689f21c1b7770735f2292c2fa667b86123354d8409d264118e1908f22dddd58fc17545e9feaae786c2414133923c2170be879ff502398f87c556d57e

    • SSDEEP

      6144:NZi9pP2JNMv8P4WyKNh6xzRnM3VVYijO9Wi7XMJRAc3ewc5n5:NZibPoKv6fNhEFMDBMWY3cu/5

    Score
    10/10
    • Detect ZGRat V1

    • ZGRat

      ZGRat is remote access trojan written in C#.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks