General

  • Target

    cf853ba5808b795bed3b7fc2ba55274f.bin

  • Size

    475KB

  • Sample

    240609-frxpssea4x

  • MD5

    887d0e6aaebc9f32a7c214c97e1d31d9

  • SHA1

    2315d551433190b096c8f60e337cc1743709f53e

  • SHA256

    a6ce3a77ed073f32ba85b270f2de2df50f860e05ffb94aca0855f98ea7127a09

  • SHA512

    cc41830c393686824aa9e9a81240af04d597c47f69822ab18429a28d118f20101f0504c620fdd64ca5ec8a6319f5852f214184816bc7bbffe4c6c5fdd50666fb

  • SSDEEP

    12288:zatvy/vs76UMpMODn1MVzBPULvEllx7uq6O6ZZ6BwN+fdkJm:zvvs76ULcnuzplduY6r6ON+CJm

Malware Config

Targets

    • Target

      cae1d06781f000cf396269e2b734d841192b2b09e7e1e9170b721ac77b70e741.zip

    • Size

      481KB

    • MD5

      cf853ba5808b795bed3b7fc2ba55274f

    • SHA1

      d669abbff493925068e637b999cb28cfbc2181a0

    • SHA256

      cae1d06781f000cf396269e2b734d841192b2b09e7e1e9170b721ac77b70e741

    • SHA512

      33e621a67af9d89580e71e995024bb9b37a7b8c0e0d305c3cc46f957613599d8f85771655767bc97559f1330ba45e4fb6570fb49502627cb14e19955025a0771

    • SSDEEP

      12288:OhlGrKeQSPEIBrX01FURb5hvdCqBFkMNi29Kc4:OrGrlzL0M9QEi2Y

    • STRRAT

      STRRAT is a remote access tool than can steal credentials and log keystrokes.

    • Drops startup file

    • Loads dropped DLL

    • Modifies file permissions

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Scheduled Task/Job

1
T1053

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks