General

  • Target

    a0cb4f7f3c939cc3fd95d8392c08b8a339da6ee21d9fb39770a2cf28a8189aa6

  • Size

    4KB

  • Sample

    240526-bn4aysac24

  • MD5

    0225c371180a7951cda9632103c92edd

  • SHA1

    c7d589cbb0c9a5b1cdaae9c7ccc3fd43a5ce177f

  • SHA256

    a0cb4f7f3c939cc3fd95d8392c08b8a339da6ee21d9fb39770a2cf28a8189aa6

  • SHA512

    104751efde2cd1cc773acf6d57dfbfe5f81e6a77ca83d8617eae3a6cbebe5f2cacce6b4ee51976234d8ba9113504e7212656f2cc3539cc2986f223b83debef46

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsDgZnA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RFnKymV44Sh

Score
10/10

Malware Config

Targets

    • Target

      a0cb4f7f3c939cc3fd95d8392c08b8a339da6ee21d9fb39770a2cf28a8189aa6

    • Size

      4KB

    • MD5

      0225c371180a7951cda9632103c92edd

    • SHA1

      c7d589cbb0c9a5b1cdaae9c7ccc3fd43a5ce177f

    • SHA256

      a0cb4f7f3c939cc3fd95d8392c08b8a339da6ee21d9fb39770a2cf28a8189aa6

    • SHA512

      104751efde2cd1cc773acf6d57dfbfe5f81e6a77ca83d8617eae3a6cbebe5f2cacce6b4ee51976234d8ba9113504e7212656f2cc3539cc2986f223b83debef46

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsDgZnA7B8mOo4jUx7OtKGc:Z0v4mUWKh9ctgC1RFnKymV44Sh

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks