General

  • Target

    673e868cb19ea890ef69957e11d08b95d761957623c36a5e3396804e7685bb44.exe

  • Size

    181KB

  • Sample

    240612-bx8l2axgnh

  • MD5

    d3d4f9479544722b50d57432447b57b0

  • SHA1

    61c78287030f58e9e3840e2415cae8e99dce4a2e

  • SHA256

    673e868cb19ea890ef69957e11d08b95d761957623c36a5e3396804e7685bb44

  • SHA512

    84ed67440e7d2c73014db09376dcb0e7db13583752054bfb8a50ae84d896d34ed5b1a7cac4d6aa6989fdf86714435fac49c1145338c2c33cc9ea6793256e3d64

  • SSDEEP

    3072:nCmlA+2TGMF85+bkRG32foUP9GmPe97UodZDO4eHsZZZZZZZZZZZZZtRP/tUlnfR:CmlV4h8JG3QUzdZDO4eHsZZZZZZZZZZ

Score
10/10

Malware Config

Extracted

Family

koiloader

C2

http://89.251.22.227/guacos.php

Attributes
  • payload_url

    https://lechiavetteusb.it/imgs/usb/logo

Targets

    • Target

      673e868cb19ea890ef69957e11d08b95d761957623c36a5e3396804e7685bb44.exe

    • Size

      181KB

    • MD5

      d3d4f9479544722b50d57432447b57b0

    • SHA1

      61c78287030f58e9e3840e2415cae8e99dce4a2e

    • SHA256

      673e868cb19ea890ef69957e11d08b95d761957623c36a5e3396804e7685bb44

    • SHA512

      84ed67440e7d2c73014db09376dcb0e7db13583752054bfb8a50ae84d896d34ed5b1a7cac4d6aa6989fdf86714435fac49c1145338c2c33cc9ea6793256e3d64

    • SSDEEP

      3072:nCmlA+2TGMF85+bkRG32foUP9GmPe97UodZDO4eHsZZZZZZZZZZZZZtRP/tUlnfR:CmlV4h8JG3QUzdZDO4eHsZZZZZZZZZZ

    Score
    10/10
    • KoiLoader

      KoiLoader is a malware loader written in C++.

    • Detects KoiLoader payload

    • Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)

MITRE ATT&CK Matrix

Tasks