General

  • Target

    S0.KvRIxPT.exe

  • Size

    42KB

  • Sample

    240517-zf69msaa3v

  • MD5

    858cbb9092153a7097a7da5e4a2195f9

  • SHA1

    4cf6fe6d834168e18430ff8632265fd93e8c9bcf

  • SHA256

    a74dac946b8d97e1d4e193d64aac8781eb32039412037a195aa10b40a19dc441

  • SHA512

    1d5795d7931b02c7cc7d17b81d52bce17da85dd03d81ac5221b8eccda0bda0fe9052925037ea44cd64a4c3fce5ab648dc2f17f784f8261ed90f10c32b1f9a02b

  • SSDEEP

    768:XgtO5EYH//4MmuZqLHSTjCKZKfgm3Ehhx:JEaDyLHSTWF7Erx

Malware Config

Extracted

Family

mercurialgrabber

C2

https://discord.com/api/webhooks/1014925257104162816/i_FgV0Vzo9Zj1gKs2wPCtFL9nQzLwfkh1frAZ_EO2HgDoESbbCIxJZtcdGID1SDoDkRZ

Targets

    • Target

      S0.KvRIxPT.exe

    • Size

      42KB

    • MD5

      858cbb9092153a7097a7da5e4a2195f9

    • SHA1

      4cf6fe6d834168e18430ff8632265fd93e8c9bcf

    • SHA256

      a74dac946b8d97e1d4e193d64aac8781eb32039412037a195aa10b40a19dc441

    • SHA512

      1d5795d7931b02c7cc7d17b81d52bce17da85dd03d81ac5221b8eccda0bda0fe9052925037ea44cd64a4c3fce5ab648dc2f17f784f8261ed90f10c32b1f9a02b

    • SSDEEP

      768:XgtO5EYH//4MmuZqLHSTjCKZKfgm3Ehhx:JEaDyLHSTWF7Erx

    • Mercurial Grabber Stealer

      Mercurial Grabber is an open source stealer targeting Chrome, Discord and some game clients as well as generic system information.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Legitimate hosting services abused for malware hosting/C2

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

1
T1005

Command and Control

Web Service

1
T1102

Tasks