General

  • Target

    6bc8675f1ecde91d6e90535aa18a328288ee6b3f09f68d2c159eb271e817f638.exe

  • Size

    5.9MB

  • Sample

    240515-btff3sag59

  • MD5

    cea3bd36e98356634a90abb7e89a7c87

  • SHA1

    18d9dcea711835f80d7a5a42ae8d1011afa211d9

  • SHA256

    6bc8675f1ecde91d6e90535aa18a328288ee6b3f09f68d2c159eb271e817f638

  • SHA512

    4db4d6d462837674ce9c1525974e82faec4c982515072ff6e55a84796edc2252e39f9776a2e1cf0a278c7226d7d86cde5bf2e305e7442e1f1cba6dc8c5b3aed0

  • SSDEEP

    24576:n+c2eZywo6zluOifT5VaXTKlw665Y9jdPXpBRYsHkDVhlYj0FOcwJQigeIE4L51S:

Score
10/10

Malware Config

Targets

    • Target

      6bc8675f1ecde91d6e90535aa18a328288ee6b3f09f68d2c159eb271e817f638.exe

    • Size

      5.9MB

    • MD5

      cea3bd36e98356634a90abb7e89a7c87

    • SHA1

      18d9dcea711835f80d7a5a42ae8d1011afa211d9

    • SHA256

      6bc8675f1ecde91d6e90535aa18a328288ee6b3f09f68d2c159eb271e817f638

    • SHA512

      4db4d6d462837674ce9c1525974e82faec4c982515072ff6e55a84796edc2252e39f9776a2e1cf0a278c7226d7d86cde5bf2e305e7442e1f1cba6dc8c5b3aed0

    • SSDEEP

      24576:n+c2eZywo6zluOifT5VaXTKlw665Y9jdPXpBRYsHkDVhlYj0FOcwJQigeIE4L51S:

    Score
    10/10
    • Detect ZGRat V1

    • ZGRat

      ZGRat is remote access trojan written in C#.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks