General

  • Target

    0e77c7eaf29e7cc81d6a5870545509a3.exe

  • Size

    2.0MB

  • Sample

    240515-evspksha45

  • MD5

    0e77c7eaf29e7cc81d6a5870545509a3

  • SHA1

    e56496e200c3246c149b41bd826b9e762fa5e534

  • SHA256

    64839df979829a8230b50891466a04e1d428f70d928205709668205669115a5e

  • SHA512

    bf85986eb8b47fc7211a6b6b48121ae0de6718c73612a4059f3bf8570a47b5848a0619c056a9b55df2760f2c5e5f30ca5a19a5d091750af8ad7bb81c5f015e18

  • SSDEEP

    49152:R6K39H/NzGjGzMErFiEntNARL3AVtsk53gEdMJ9O:R6KnjrLntNAR2tPfO

Malware Config

Targets

    • Target

      0e77c7eaf29e7cc81d6a5870545509a3.exe

    • Size

      2.0MB

    • MD5

      0e77c7eaf29e7cc81d6a5870545509a3

    • SHA1

      e56496e200c3246c149b41bd826b9e762fa5e534

    • SHA256

      64839df979829a8230b50891466a04e1d428f70d928205709668205669115a5e

    • SHA512

      bf85986eb8b47fc7211a6b6b48121ae0de6718c73612a4059f3bf8570a47b5848a0619c056a9b55df2760f2c5e5f30ca5a19a5d091750af8ad7bb81c5f015e18

    • SSDEEP

      49152:R6K39H/NzGjGzMErFiEntNARL3AVtsk53gEdMJ9O:R6KnjrLntNAR2tPfO

    • Detect ZGRat V1

    • ZGRat

      ZGRat is remote access trojan written in C#.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Collection

Data from Local System

1
T1005

Tasks