General

  • Target

    3fe6064d693a32ebf17af6e73b22dd7d.exe

  • Size

    1.8MB

  • Sample

    240620-vwz32syfjc

  • MD5

    3fe6064d693a32ebf17af6e73b22dd7d

  • SHA1

    d2734d1e21ec4b5b4883e603527dea2b6dd4714b

  • SHA256

    5b8c7829500e73f58080b635970a9b7898683a9b99e425595eca9dc3fd1c5382

  • SHA512

    8ee9eb8de35a648625780f6577c9968bfa2b2504c5081f66c708899d392d5cc2166b2d593c22ad0e19984e6c156553ae37702f8953bf3e112a8d6f4aaff91c77

  • SSDEEP

    12288:uvsXZv8km0OHcbGbvzWHz0Hnquwxq+t0ssFWylkkoAbtEaJwfNqbYS2VbICKMIUf:ZfPz0Hyzt0ssFlSjKTzi

Malware Config

Targets

    • Target

      3fe6064d693a32ebf17af6e73b22dd7d.exe

    • Size

      1.8MB

    • MD5

      3fe6064d693a32ebf17af6e73b22dd7d

    • SHA1

      d2734d1e21ec4b5b4883e603527dea2b6dd4714b

    • SHA256

      5b8c7829500e73f58080b635970a9b7898683a9b99e425595eca9dc3fd1c5382

    • SHA512

      8ee9eb8de35a648625780f6577c9968bfa2b2504c5081f66c708899d392d5cc2166b2d593c22ad0e19984e6c156553ae37702f8953bf3e112a8d6f4aaff91c77

    • SSDEEP

      12288:uvsXZv8km0OHcbGbvzWHz0Hnquwxq+t0ssFWylkkoAbtEaJwfNqbYS2VbICKMIUf:ZfPz0Hyzt0ssFlSjKTzi

    • SectopRAT

      SectopRAT is a remote access trojan first seen in November 2019.

    • SectopRAT payload

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Discovery

Query Registry

1
T1012

Collection

Data from Local System

2
T1005

Tasks