General

  • Target

    S0.KvRIxPT.exe

  • Size

    42KB

  • MD5

    858cbb9092153a7097a7da5e4a2195f9

  • SHA1

    4cf6fe6d834168e18430ff8632265fd93e8c9bcf

  • SHA256

    a74dac946b8d97e1d4e193d64aac8781eb32039412037a195aa10b40a19dc441

  • SHA512

    1d5795d7931b02c7cc7d17b81d52bce17da85dd03d81ac5221b8eccda0bda0fe9052925037ea44cd64a4c3fce5ab648dc2f17f784f8261ed90f10c32b1f9a02b

  • SSDEEP

    768:XgtO5EYH//4MmuZqLHSTjCKZKfgm3Ehhx:JEaDyLHSTWF7Erx

Score
10/10

Malware Config

Extracted

Family

mercurialgrabber

C2

https://discord.com/api/webhooks/1014925257104162816/i_FgV0Vzo9Zj1gKs2wPCtFL9nQzLwfkh1frAZ_EO2HgDoESbbCIxJZtcdGID1SDoDkRZ

Signatures

  • Mercurialgrabber family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • S0.KvRIxPT.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections