General

  • Target

    virussign.com_b07a6671f8bfb6853c6a6ee4d3976d00.vir

  • Size

    4KB

  • Sample

    240528-vzbjvsdb61

  • MD5

    b07a6671f8bfb6853c6a6ee4d3976d00

  • SHA1

    e1fc693d730c1e3b3772af9c1c16e35a3afa16b7

  • SHA256

    228c13978462a72c4abe3f3b3159432c761478b855a9175f76e2ac794027340c

  • SHA512

    3e70f4432bf9f07c7af68aa9aa9e8231b52ffdae39e440707106b51a9a6f885e8519788afa4a329640e6c03f69bfebeb810fac21844ec7d941e09dbc87a09103

  • SSDEEP

    48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsNIJN6nA7B8mOo4jUx7OtKGa:Z0v4mUWKh9ctgC1ReIJN6nKymV44Shy/

Score
10/10

Malware Config

Targets

    • Target

      virussign.com_b07a6671f8bfb6853c6a6ee4d3976d00.vir

    • Size

      4KB

    • MD5

      b07a6671f8bfb6853c6a6ee4d3976d00

    • SHA1

      e1fc693d730c1e3b3772af9c1c16e35a3afa16b7

    • SHA256

      228c13978462a72c4abe3f3b3159432c761478b855a9175f76e2ac794027340c

    • SHA512

      3e70f4432bf9f07c7af68aa9aa9e8231b52ffdae39e440707106b51a9a6f885e8519788afa4a329640e6c03f69bfebeb810fac21844ec7d941e09dbc87a09103

    • SSDEEP

      48:Zdni+Wyi18DN0nCvTaE6nc9fhXcGEY3sJd9ga91RsNIJN6nA7B8mOo4jUx7OtKGa:Z0v4mUWKh9ctgC1ReIJN6nKymV44Shy/

    Score
    10/10
    • Upatre

      Upatre is a generic malware downloader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks