General

  • Target

    virussign.com_5e9d32306f4ef655d4a768f5d5822bb0.vir

  • Size

    4KB

  • Sample

    240528-vrrk4sea79

  • MD5

    5e9d32306f4ef655d4a768f5d5822bb0

  • SHA1

    e7ad13297718b6d0f67e84764875930957db813a

  • SHA256

    8c402ac40afddc4842ae2f8bf48c762512a81d930b9b16591e36780b556e84de

  • SHA512

    1f9738031e95fe005579e9eabf71e79f05440bbc122b8c7160e7dd672934952e605719215039186449b3d99e7f0556a11bc3015d43d6f636292fb2916008cd99

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsyDknA7B8mOo4jUx7OtKGc3Q:Z0v4mUWKh9ctgC1RFknKymV44ShiY/

Score
10/10

Malware Config

Targets

    • Target

      virussign.com_5e9d32306f4ef655d4a768f5d5822bb0.vir

    • Size

      4KB

    • MD5

      5e9d32306f4ef655d4a768f5d5822bb0

    • SHA1

      e7ad13297718b6d0f67e84764875930957db813a

    • SHA256

      8c402ac40afddc4842ae2f8bf48c762512a81d930b9b16591e36780b556e84de

    • SHA512

      1f9738031e95fe005579e9eabf71e79f05440bbc122b8c7160e7dd672934952e605719215039186449b3d99e7f0556a11bc3015d43d6f636292fb2916008cd99

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsyDknA7B8mOo4jUx7OtKGc3Q:Z0v4mUWKh9ctgC1RFknKymV44ShiY/

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks