General

  • Target

    f0699de74b6274011f91036c3daafc4aae3e49e2210be14ea06a8d478248c151.zip

  • Size

    481KB

  • Sample

    240528-b269rsaa7w

  • MD5

    0bd6891d55ba2fc4b16da35243710fc0

  • SHA1

    148901af7e43cd04bfaaa393d1abaf0f91e29f5e

  • SHA256

    f0699de74b6274011f91036c3daafc4aae3e49e2210be14ea06a8d478248c151

  • SHA512

    1ca26438fd51937b1091883198309518984eb4f1bdc3de3fbaca1ac5d63b2c31a5ab79f3d901d9e2a0e90739ab2b144f74770be4daaf7b73845b4d6fb3016078

  • SSDEEP

    12288:ublFMKeQSPEXjwVfgFJRb5hokCl24Lpty4qKcV:uxFMlwofcpKjy4S

Malware Config

Targets

    • Target

      f0699de74b6274011f91036c3daafc4aae3e49e2210be14ea06a8d478248c151.zip

    • Size

      481KB

    • MD5

      0bd6891d55ba2fc4b16da35243710fc0

    • SHA1

      148901af7e43cd04bfaaa393d1abaf0f91e29f5e

    • SHA256

      f0699de74b6274011f91036c3daafc4aae3e49e2210be14ea06a8d478248c151

    • SHA512

      1ca26438fd51937b1091883198309518984eb4f1bdc3de3fbaca1ac5d63b2c31a5ab79f3d901d9e2a0e90739ab2b144f74770be4daaf7b73845b4d6fb3016078

    • SSDEEP

      12288:ublFMKeQSPEXjwVfgFJRb5hokCl24Lpty4qKcV:uxFMlwofcpKjy4S

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Accesses Microsoft Outlook profiles

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Collection

Email Collection

1
T1114

Tasks