General

  • Target

    cae70eaf4f15e4c111a6d6c015f86633bc5836dc6efff28298a5745852c52a51

  • Size

    1.8MB

  • Sample

    240615-cjg3lawang

  • MD5

    4cf68b5153ef9fef0913eaac33835ff6

  • SHA1

    ca9f7248c04ac4720735a387a56e474ab08dc438

  • SHA256

    cae70eaf4f15e4c111a6d6c015f86633bc5836dc6efff28298a5745852c52a51

  • SHA512

    616e9ff51db040627157eca8bda77842c9ae3d675014f24b0ab5f25aab6877b0fcfb56aec09d6545c7fc175b420234e95f27b48b109665273aa3fd9185b3b3d0

  • SSDEEP

    49152:VvMW2NU1HlwuKfJTkYQknzTAixG00q5VWy7EeNpZ:V0hNOFwu4QknzTAixBPtQAz

Malware Config

Targets

    • Target

      cae70eaf4f15e4c111a6d6c015f86633bc5836dc6efff28298a5745852c52a51

    • Size

      1.8MB

    • MD5

      4cf68b5153ef9fef0913eaac33835ff6

    • SHA1

      ca9f7248c04ac4720735a387a56e474ab08dc438

    • SHA256

      cae70eaf4f15e4c111a6d6c015f86633bc5836dc6efff28298a5745852c52a51

    • SHA512

      616e9ff51db040627157eca8bda77842c9ae3d675014f24b0ab5f25aab6877b0fcfb56aec09d6545c7fc175b420234e95f27b48b109665273aa3fd9185b3b3d0

    • SSDEEP

      49152:VvMW2NU1HlwuKfJTkYQknzTAixG00q5VWy7EeNpZ:V0hNOFwu4QknzTAixBPtQAz

    • Banload

      Banload variants download malicious files, then install and execute the files.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

1
T1082

Tasks