General

  • Target

    832448fcb3cd222b62a08cdc9fabf2e6bffe92a6bdbcf481a0edcec65f965efa

  • Size

    221.2MB

  • Sample

    240622-bmv8ystgpp

  • MD5

    5a79d71298c80aaf94cad9354d687acc

  • SHA1

    0e2edb5daa563922bee17b0cf39a87b7dff25018

  • SHA256

    832448fcb3cd222b62a08cdc9fabf2e6bffe92a6bdbcf481a0edcec65f965efa

  • SHA512

    ab81a7ac51d857888a863fab15bd69d85dbf8cc636bc814915fb79e22d12b7cc2efe4b528fe0988a0fce68703dedd7d9e203619a354c16cffd9746fe6898abaa

  • SSDEEP

    6291456:D00QRvCviS8vs/tQB6M3SRdphg/UUJJ4eeZr1Mr+/0Wt7sgWZQ:+RvCviSm3SPg/Uyk1d/0WJ

Malware Config

Targets

    • Target

      832448fcb3cd222b62a08cdc9fabf2e6bffe92a6bdbcf481a0edcec65f965efa

    • Size

      221.2MB

    • MD5

      5a79d71298c80aaf94cad9354d687acc

    • SHA1

      0e2edb5daa563922bee17b0cf39a87b7dff25018

    • SHA256

      832448fcb3cd222b62a08cdc9fabf2e6bffe92a6bdbcf481a0edcec65f965efa

    • SHA512

      ab81a7ac51d857888a863fab15bd69d85dbf8cc636bc814915fb79e22d12b7cc2efe4b528fe0988a0fce68703dedd7d9e203619a354c16cffd9746fe6898abaa

    • SSDEEP

      6291456:D00QRvCviS8vs/tQB6M3SRdphg/UUJJ4eeZr1Mr+/0Wt7sgWZQ:+RvCviSm3SPg/Uyk1d/0WJ

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

System Information Discovery

3
T1082

Peripheral Device Discovery

1
T1120

Tasks