General

  • Target

    pa collective agreement pay 36066.js

  • Size

    23.2MB

  • Sample

    240622-qstdwazeja

  • MD5

    7df2e7c08396b3b063cef4b67cc8ddfa

  • SHA1

    97a4d853506d5fe06486e8ada4a0fbb4fa80c66e

  • SHA256

    9f23b074d11f7c319aa0cb4393f227de1f66523e55aae48a94059f47d3652572

  • SHA512

    fcc56a9f735e4b1eb101f460fbbcd72256af3be4cd3e4a3a9e2e76cab2700fef5668686308d1b929c4ca1dca5f5041877727db212073c816b22402d0a0686c96

  • SSDEEP

    49152:+tM08dPXWR4ba/JOtdF5pHE2lsfiaahM3o43ORV59VDKtDxtM08dPXWR4ba/JOtz:gc43myc43myc43myc43myc43ml

Malware Config

Targets

    • Target

      pa collective agreement pay 36066.js

    • Size

      23.2MB

    • MD5

      7df2e7c08396b3b063cef4b67cc8ddfa

    • SHA1

      97a4d853506d5fe06486e8ada4a0fbb4fa80c66e

    • SHA256

      9f23b074d11f7c319aa0cb4393f227de1f66523e55aae48a94059f47d3652572

    • SHA512

      fcc56a9f735e4b1eb101f460fbbcd72256af3be4cd3e4a3a9e2e76cab2700fef5668686308d1b929c4ca1dca5f5041877727db212073c816b22402d0a0686c96

    • SSDEEP

      49152:+tM08dPXWR4ba/JOtdF5pHE2lsfiaahM3o43ORV59VDKtDxtM08dPXWR4ba/JOtz:gc43myc43myc43myc43myc43ml

    • GootLoader

      JavaScript loader known for delivering other families such as Gootkit and Cobaltstrike.

    • Blocklisted process makes network request

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

JavaScript

1
T1059.007

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks