General

  • Target

    22ce45aa4ec31f4937872fb15d6ae787168c0f5a8399f514dd69e4eecbdc075c.lnk

  • Size

    2KB

  • Sample

    240606-rkpldsfb9z

  • MD5

    6bef4f06938cf2569a3ad26a9827269a

  • SHA1

    e9a2dbcf2bf6bead0f46c60b7b8b5ffcf0dcfc50

  • SHA256

    22ce45aa4ec31f4937872fb15d6ae787168c0f5a8399f514dd69e4eecbdc075c

  • SHA512

    989181fdb9e591f113d54e18c31f093f681b9b30b3651d06c81fd202a51735079b8fe90f5bc708428ec973eefcf83ea7b3e982786d7c19a19d1512965c739b9c

Malware Config

Extracted

Family

koiloader

C2

http://81.19.141.115/marasmus.php

Attributes
  • payload_url

    https://www.dsestimation.com/wp-content/uploads/2015/10

Targets

    • Target

      22ce45aa4ec31f4937872fb15d6ae787168c0f5a8399f514dd69e4eecbdc075c.lnk

    • Size

      2KB

    • MD5

      6bef4f06938cf2569a3ad26a9827269a

    • SHA1

      e9a2dbcf2bf6bead0f46c60b7b8b5ffcf0dcfc50

    • SHA256

      22ce45aa4ec31f4937872fb15d6ae787168c0f5a8399f514dd69e4eecbdc075c

    • SHA512

      989181fdb9e591f113d54e18c31f093f681b9b30b3651d06c81fd202a51735079b8fe90f5bc708428ec973eefcf83ea7b3e982786d7c19a19d1512965c739b9c

    • KoiLoader

      KoiLoader is a malware loader written in C++.

    • Detects KoiLoader payload

    • Blocklisted process makes network request

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

2
T1059

PowerShell

1
T1059.001

JavaScript

1
T1059.007

Scheduled Task/Job

1
T1053

Persistence

Scheduled Task/Job

1
T1053

Privilege Escalation

Scheduled Task/Job

1
T1053

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks