General

  • Target

    1fc262431bf4d498c60edf371650da94b349addd1cb1ef3d63c3cf6578196480

  • Size

    1.2MB

  • Sample

    240515-ckswgscg43

  • MD5

    d9015a5146e13d6d4a23d908e9b863a1

  • SHA1

    cb6436ab865dc1df554063d5fbf3b6ceb8d58712

  • SHA256

    1fc262431bf4d498c60edf371650da94b349addd1cb1ef3d63c3cf6578196480

  • SHA512

    684f19b4ec97fd766054250ab9550e70a3a3bec47d83dfd2e824f4f9034e77c49948b629bae77ba0f454b4ecf904a5d8feedd7904c90292c609856323f4ef39d

  • SSDEEP

    24576:DqDEvCTbMWu7rQYlBQcBiT6rprG8aBJKH6bjq49YWNO:DTvC/MTQYxsWR7aBJKH6bG49YW

Malware Config

Targets

    • Target

      1fc262431bf4d498c60edf371650da94b349addd1cb1ef3d63c3cf6578196480

    • Size

      1.2MB

    • MD5

      d9015a5146e13d6d4a23d908e9b863a1

    • SHA1

      cb6436ab865dc1df554063d5fbf3b6ceb8d58712

    • SHA256

      1fc262431bf4d498c60edf371650da94b349addd1cb1ef3d63c3cf6578196480

    • SHA512

      684f19b4ec97fd766054250ab9550e70a3a3bec47d83dfd2e824f4f9034e77c49948b629bae77ba0f454b4ecf904a5d8feedd7904c90292c609856323f4ef39d

    • SSDEEP

      24576:DqDEvCTbMWu7rQYlBQcBiT6rprG8aBJKH6bjq49YWNO:DTvC/MTQYxsWR7aBJKH6bG49YW

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • Detect ZGRat V1

    • ZGRat

      ZGRat is remote access trojan written in C#.

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks