General

  • Target

    2756-1-0x00000000012A0000-0x00000000012B9000-memory.dmp

  • Size

    100KB

  • Sample

    240527-mswmfshf74

  • MD5

    43ac0ade3097819d60a2fe0897b93668

  • SHA1

    f127d66ba9be1b58d47a471d3b47fa1b2c4c89bf

  • SHA256

    4ec643d9c0062fa2199b3999dc13ef9deb4b5fb9d890f3f03fdec9d5c9665e2c

  • SHA512

    26be150f90234b7537a4cbc2cef18c0864bb3a1aa145577e03eda1e25256c155d4356efcd887862cd3293b5ab2f98d11e728f3b1d285dcc8683de46adc05f240

  • SSDEEP

    1536:S/v673IbnUpotVn/bwTJTL/CvAcArR9i/0EwhQNHI66:S/vI4cotVUF/0AcArR8MEsQNof

Score
10/10

Malware Config

Extracted

Family

pikabot

C2

https://109.199.99.131:13721

https://154.38.175.241:13721

https://148.113.141.220:2224

https://23.226.138.143:2083

https://89.117.23.186:5686

https://23.226.138.161:5242

https://103.82.243.5:13721

https://145.239.135.24:5243

https://185.179.217.216:9785

https://154.12.248.41:5000

https://178.18.246.136:2078

https://141.95.106.106:2967

https://104.129.55.105:2223

https://57.128.165.176:13721

https://89.117.23.185:2221

https://86.38.225.106:2221

https://37.60.242.86:2967

https://37.60.242.85:9785

https://89.117.23.34:5938

https://154.12.233.66:2224

Targets

    • Target

      2756-1-0x00000000012A0000-0x00000000012B9000-memory.dmp

    • Size

      100KB

    • MD5

      43ac0ade3097819d60a2fe0897b93668

    • SHA1

      f127d66ba9be1b58d47a471d3b47fa1b2c4c89bf

    • SHA256

      4ec643d9c0062fa2199b3999dc13ef9deb4b5fb9d890f3f03fdec9d5c9665e2c

    • SHA512

      26be150f90234b7537a4cbc2cef18c0864bb3a1aa145577e03eda1e25256c155d4356efcd887862cd3293b5ab2f98d11e728f3b1d285dcc8683de46adc05f240

    • SSDEEP

      1536:S/v673IbnUpotVn/bwTJTL/CvAcArR9i/0EwhQNHI66:S/vI4cotVUF/0AcArR8MEsQNof

    Score
    3/10

MITRE ATT&CK Matrix

Tasks