General

  • Target

    9aa1374234a1e7ceb98ab263aa4124786ad7ec87e7a1ca945470c00d7160cc11

  • Size

    5.5MB

  • Sample

    240611-bdjtkayclp

  • MD5

    3db919a39a4f78d41d760479e9b850fc

  • SHA1

    8e0e32db18f56dc47b6205cef7c58373605822cc

  • SHA256

    9aa1374234a1e7ceb98ab263aa4124786ad7ec87e7a1ca945470c00d7160cc11

  • SHA512

    9a5f6cd6960638bd62ef6ca48e5bcfb0958d58b0bbab25195bc65aa451cb792e7f58fd8e782f3e334cd626d81647e176e7870e2c7821b02a63a009f32010631d

  • SSDEEP

    98304:juzJRlT3NYn5UD/1Z/jqxjBH7SeNWDhdXWu2L8+aU/S/VQQPXmqskC:juJRlbHD/7jUjBH7SeNWDDXWu2j7Qfm1

Score
10/10

Malware Config

Extracted

Family

danabot

C2

23.254.253.134:443

104.234.10.89:443

104.234.119.29:443

142.11.244.14:443

Attributes
  • embedded_hash

    89B90FCAE14E80221BEFC7F02C3615D6

  • type

    loader

Targets

    • Target

      9aa1374234a1e7ceb98ab263aa4124786ad7ec87e7a1ca945470c00d7160cc11

    • Size

      5.5MB

    • MD5

      3db919a39a4f78d41d760479e9b850fc

    • SHA1

      8e0e32db18f56dc47b6205cef7c58373605822cc

    • SHA256

      9aa1374234a1e7ceb98ab263aa4124786ad7ec87e7a1ca945470c00d7160cc11

    • SHA512

      9a5f6cd6960638bd62ef6ca48e5bcfb0958d58b0bbab25195bc65aa451cb792e7f58fd8e782f3e334cd626d81647e176e7870e2c7821b02a63a009f32010631d

    • SSDEEP

      98304:juzJRlT3NYn5UD/1Z/jqxjBH7SeNWDhdXWu2L8+aU/S/VQQPXmqskC:juJRlbHD/7jUjBH7SeNWDDXWu2j7Qfm1

    Score
    10/10
    • Danabot

      Danabot is a modular banking Trojan that has been linked with other malware.

    • Blocklisted process makes network request

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Tasks