General

  • Target

    ad747e59d4d15a7585dc5aa943ecd9c3258a7de57a7269c882ff436932f51e94.zip

  • Size

    452KB

  • Sample

    240607-j4eljadb2w

  • MD5

    7ca5588c60e103a7ec2531f10f70e7b4

  • SHA1

    12d63977451d2bd0acc917975abb9148a8f9b8d2

  • SHA256

    ad747e59d4d15a7585dc5aa943ecd9c3258a7de57a7269c882ff436932f51e94

  • SHA512

    ac1814c1300f7cb87ff3e106aeba2944fd01f3306d35112b99cbd34b3449e218a54ffbba6198a7280cb74438f745f7ad57279a5d17b0bf334359e32e380819b9

  • SSDEEP

    12288:WUcrdL9fstlH/MH0nSQkGrorW3J+RMhdQE6ZBj2l:wdL9fSlfGY2KorW5+RMhdQEip8

Malware Config

Targets

    • Target

      ad747e59d4d15a7585dc5aa943ecd9c3258a7de57a7269c882ff436932f51e94.zip

    • Size

      452KB

    • MD5

      7ca5588c60e103a7ec2531f10f70e7b4

    • SHA1

      12d63977451d2bd0acc917975abb9148a8f9b8d2

    • SHA256

      ad747e59d4d15a7585dc5aa943ecd9c3258a7de57a7269c882ff436932f51e94

    • SHA512

      ac1814c1300f7cb87ff3e106aeba2944fd01f3306d35112b99cbd34b3449e218a54ffbba6198a7280cb74438f745f7ad57279a5d17b0bf334359e32e380819b9

    • SSDEEP

      12288:WUcrdL9fstlH/MH0nSQkGrorW3J+RMhdQE6ZBj2l:wdL9fSlfGY2KorW5+RMhdQEip8

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks