General

  • Target

    9d736ea2310a978dd03952a34ceed2e2b189305cfa52b5bd055e12d530e4ff1d

  • Size

    6.1MB

  • Sample

    240528-vrge5sea72

  • MD5

    019a22413204f5bd60a38281764c5405

  • SHA1

    1cc6fccbd64ad47867f8cfa3c12fa10a86f63580

  • SHA256

    9d736ea2310a978dd03952a34ceed2e2b189305cfa52b5bd055e12d530e4ff1d

  • SHA512

    76e8141c60689eb1aa0f20dc03312622426d084ffd5258164bdbb9edf4dcf45e2b2f9a6a041ac8e3e256abfc614b661e98bbfdb420fc7eeb7d269488b814ccd5

  • SSDEEP

    98304:ocfIsUtkyBXIunZXaoX90PE0Pno0PbvH8FpRDCP1nxJGV:ocfIsYkXunwbfDcT41n6

Score
10/10

Malware Config

Targets

    • Target

      9d736ea2310a978dd03952a34ceed2e2b189305cfa52b5bd055e12d530e4ff1d

    • Size

      6.1MB

    • MD5

      019a22413204f5bd60a38281764c5405

    • SHA1

      1cc6fccbd64ad47867f8cfa3c12fa10a86f63580

    • SHA256

      9d736ea2310a978dd03952a34ceed2e2b189305cfa52b5bd055e12d530e4ff1d

    • SHA512

      76e8141c60689eb1aa0f20dc03312622426d084ffd5258164bdbb9edf4dcf45e2b2f9a6a041ac8e3e256abfc614b661e98bbfdb420fc7eeb7d269488b814ccd5

    • SSDEEP

      98304:ocfIsUtkyBXIunZXaoX90PE0Pno0PbvH8FpRDCP1nxJGV:ocfIsYkXunwbfDcT41n6

    Score
    10/10
    • Detects HijackLoader (aka IDAT Loader)

    • HijackLoader

      HijackLoader is a multistage loader first seen in 2023.

    • ACProtect 1.3x - 1.4x DLL software

      Detects file using ACProtect software.

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks