General

  • Target

    Proof Of Payment.js

  • Size

    829KB

  • Sample

    240606-spms2agg94

  • MD5

    a4032522c72cd09ce0038131c668046b

  • SHA1

    f4168f40910558c77e5be2e5a883d9c99ced4bbc

  • SHA256

    f8594a3befdb1650618150f76d924aa2ef568676dee558b9c2640900eb00aa27

  • SHA512

    677b8470b6bbd86c0f026ec60491b0b8e3215c503138cfb74e2750fba0824d659ffad3d35d6b75093b60b8636fa8f8ebc86b394e68794a411d3e889648a7afa2

  • SSDEEP

    6144:XQNzmAgFd0XRVnBZUeaNwiyW3XhsVGqmpx6UydsbvfCWTxTq8tfy8V1ptpsHIg55:gx

Malware Config

Targets

    • Target

      Proof Of Payment.js

    • Size

      829KB

    • MD5

      a4032522c72cd09ce0038131c668046b

    • SHA1

      f4168f40910558c77e5be2e5a883d9c99ced4bbc

    • SHA256

      f8594a3befdb1650618150f76d924aa2ef568676dee558b9c2640900eb00aa27

    • SHA512

      677b8470b6bbd86c0f026ec60491b0b8e3215c503138cfb74e2750fba0824d659ffad3d35d6b75093b60b8636fa8f8ebc86b394e68794a411d3e889648a7afa2

    • SSDEEP

      6144:XQNzmAgFd0XRVnBZUeaNwiyW3XhsVGqmpx6UydsbvfCWTxTq8tfy8V1ptpsHIg55:gx

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

JavaScript

1
T1059.007

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks