General
-
Target
0e4c4d9f7b2ee56acdd9b3da668e2da3.bin
-
Size
676KB
-
Sample
240616-bdbsyssena
-
MD5
1e5c50982a94b72e8a5ff33da4d53efc
-
SHA1
e19448065a35aa5027ad9aa8f5f94a5dd3b402f0
-
SHA256
60bc196e60e29a55ec882753e03883834e0df25d93ab6848b738b3d3a5b0cdaa
-
SHA512
dd550a2d1131a830ca3e5ab9057e9052d15aa36cd98222a6a78db48f2bfbe650857eb6b21b70d453175fc67d3dc356d5cd1c0b66aaa3bcbe1b1cc9284c29aede
-
SSDEEP
12288:xR5qGsqRk5cb+Kr+/IRRlUFIY0qq5Qm3b/ZgkWlBJMn1LH11i:L5Lxrg0RlIID5Qm3bBge1LK
Static task
static1
Behavioral task
behavioral1
Sample
e346a199826939f2970cdd5337010e08cd761c0dfa35965afb404a04489ec0ed.exe
Resource
win7-20240611-en
Malware Config
Extracted
nanocore
1.2.2.0
vjhelena.duckdns.org:54880
alibabaforwader10.ddns.net:54880
a387c389-48e1-4208-8dfc-04ffe53ec013
-
activate_away_mode
true
-
backup_connection_host
alibabaforwader10.ddns.net
-
backup_dns_server
8.8.4.4
-
buffer_size
65535
-
build_time
2024-02-09T13:56:51.135504536Z
-
bypass_user_account_control
true
- bypass_user_account_control_data
-
clear_access_control
true
-
clear_zone_identifier
false
-
connect_delay
4000
-
connection_port
54880
-
default_group
MAY
-
enable_debug_mode
true
-
gc_threshold
1.048576e+07
-
keep_alive_timeout
30000
-
keyboard_logging
false
-
lan_timeout
2500
-
max_packet_size
1.048576e+07
-
mutex
a387c389-48e1-4208-8dfc-04ffe53ec013
-
mutex_timeout
5000
-
prevent_system_sleep
false
-
primary_connection_host
vjhelena.duckdns.org
-
primary_dns_server
8.8.8.8
-
request_elevation
true
-
restart_delay
5000
-
run_delay
0
-
run_on_startup
true
-
set_critical_process
true
-
timeout_interval
5000
-
use_custom_dns_server
false
-
version
1.2.2.0
-
wan_timeout
8000
Targets
-
-
Target
e346a199826939f2970cdd5337010e08cd761c0dfa35965afb404a04489ec0ed.exe
-
Size
820KB
-
MD5
0e4c4d9f7b2ee56acdd9b3da668e2da3
-
SHA1
11189f4174bdeb36fb31ff8a7b2489641dd144be
-
SHA256
e346a199826939f2970cdd5337010e08cd761c0dfa35965afb404a04489ec0ed
-
SHA512
a0b5de3eef3de57468a770f596c98d066eae36d538a9bc0d3e8550d6a4b21c0974deab2cc093bc612a89d935cde902c571ca92f2a61ec6d40bea0d52047df9b9
-
SSDEEP
12288:xxtg61jjk0LAta9AjjNw5DI+J/0oI3QCdiOc8f/TTRptDGiwFMdWefQS4XhEc:xg61jjk0LAta9AODIz88f///dbfQSeK
-
Command and Scripting Interpreter: PowerShell
Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Suspicious use of SetThreadContext
-