General

  • Target

    e31eca26eebc6c55841ba9012aef2e64af914e13d85be5eed4cfee7d18b7cc44.exe

  • Size

    4.1MB

  • Sample

    240606-mcg45adg74

  • MD5

    e29c083b993670853ad8cc452b1cb4d1

  • SHA1

    fce7f4d659a7cf6ca079fa26d30cbb185f9e676a

  • SHA256

    e31eca26eebc6c55841ba9012aef2e64af914e13d85be5eed4cfee7d18b7cc44

  • SHA512

    3937c2cd8e11722eac10b57b287b5340caa2604ef4f5be338f39e1d7fb8f9fcd82078503650aa4b70a2dfe9d3e1b3b7bb35c287c4e7f1683a574731d278e0fc8

  • SSDEEP

    98304:JGrnwiB2dYFBQLVw0Jv37FWi1chPr/xRmmjECQgDNU:JG7LuY/yhvJWf/qmwCQmU

Malware Config

Targets

    • Target

      e31eca26eebc6c55841ba9012aef2e64af914e13d85be5eed4cfee7d18b7cc44.exe

    • Size

      4.1MB

    • MD5

      e29c083b993670853ad8cc452b1cb4d1

    • SHA1

      fce7f4d659a7cf6ca079fa26d30cbb185f9e676a

    • SHA256

      e31eca26eebc6c55841ba9012aef2e64af914e13d85be5eed4cfee7d18b7cc44

    • SHA512

      3937c2cd8e11722eac10b57b287b5340caa2604ef4f5be338f39e1d7fb8f9fcd82078503650aa4b70a2dfe9d3e1b3b7bb35c287c4e7f1683a574731d278e0fc8

    • SSDEEP

      98304:JGrnwiB2dYFBQLVw0Jv37FWi1chPr/xRmmjECQgDNU:JG7LuY/yhvJWf/qmwCQmU

    • Glupteba

      Glupteba is a modular loader written in Golang with various components.

    • Glupteba payload

    • Modifies boot configuration data using bcdedit

    • Modifies Windows Firewall

    • Possible attempt to disable PatchGuard

      Rootkits can use kernel patching to embed themselves in an operating system.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

2
T1059

PowerShell

1
T1059.001

Scheduled Task/Job

1
T1053

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Scheduled Task/Job

1
T1053

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Scheduled Task/Job

1
T1053

Defense Evasion

Impair Defenses

2
T1562

Disable or Modify System Firewall

1
T1562.004

Impact

Inhibit System Recovery

1
T1490

Tasks