General

  • Target

    2024-06-16_1e2a8e1d7ef4f1b6afcfca6ff0dc0923_karagany_mafia

  • Size

    308KB

  • Sample

    240616-yhwegsvcpe

  • MD5

    1e2a8e1d7ef4f1b6afcfca6ff0dc0923

  • SHA1

    b496d0e9cae055bda8552cdf24708532976fb64f

  • SHA256

    d2e89e95fd9c866dbd1523b31fa7f5fa65cb9a72bb35b845ea61034fc3a34146

  • SHA512

    7be330690117e51795fc946e85c7f8dce90b7f9a2718f9f4a6e875dc4c63a74f3771c0c14950a450693375cdb3683464f4a0e956e3c846b3ddfb890d1b572199

  • SSDEEP

    6144:JzL7ShWDLVzVNam6GxI29dqG3KdYAYqTuPZp:XDHNam62ZdKmZmuPH

Malware Config

Targets

    • Target

      2024-06-16_1e2a8e1d7ef4f1b6afcfca6ff0dc0923_karagany_mafia

    • Size

      308KB

    • MD5

      1e2a8e1d7ef4f1b6afcfca6ff0dc0923

    • SHA1

      b496d0e9cae055bda8552cdf24708532976fb64f

    • SHA256

      d2e89e95fd9c866dbd1523b31fa7f5fa65cb9a72bb35b845ea61034fc3a34146

    • SHA512

      7be330690117e51795fc946e85c7f8dce90b7f9a2718f9f4a6e875dc4c63a74f3771c0c14950a450693375cdb3683464f4a0e956e3c846b3ddfb890d1b572199

    • SSDEEP

      6144:JzL7ShWDLVzVNam6GxI29dqG3KdYAYqTuPZp:XDHNam62ZdKmZmuPH

    • GandCrab payload

    • Gandcrab

      Gandcrab is a Trojan horse that encrypts files on a computer.

    • Detects Reflective DLL injection artifacts

    • Detects ransomware indicator

    • Gandcrab Payload

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks