General

  • Target

    fd77345f31986cc1cd11bf9000605dc29d3a0cc8c36440edd73649e5334c78ca

  • Size

    98KB

  • Sample

    240623-gk73mawajk

  • MD5

    2257282724082a00ce4a0b1ded95aca4

  • SHA1

    a389a1937606ab25ddb8e2f50d6bc66272d567ea

  • SHA256

    fd77345f31986cc1cd11bf9000605dc29d3a0cc8c36440edd73649e5334c78ca

  • SHA512

    cdb50b486a7186eb567aef31f3f80cf731a7d3478bff412fb8270d155f31be3a966287ac26025e7d9d23e76c87f542bf5bb817173fdb1de800fa4fff8dba2f2c

  • SSDEEP

    1536:7CsqDw2ost58PNkDtPMpcJBO9YcCF11jVEyy:mpjZ+cJBSY9djVEh

Malware Config

Extracted

Family

warzonerat

C2

wealth.warzonedns.com:5202

Targets

    • Target

      fd77345f31986cc1cd11bf9000605dc29d3a0cc8c36440edd73649e5334c78ca

    • Size

      98KB

    • MD5

      2257282724082a00ce4a0b1ded95aca4

    • SHA1

      a389a1937606ab25ddb8e2f50d6bc66272d567ea

    • SHA256

      fd77345f31986cc1cd11bf9000605dc29d3a0cc8c36440edd73649e5334c78ca

    • SHA512

      cdb50b486a7186eb567aef31f3f80cf731a7d3478bff412fb8270d155f31be3a966287ac26025e7d9d23e76c87f542bf5bb817173fdb1de800fa4fff8dba2f2c

    • SSDEEP

      1536:7CsqDw2ost58PNkDtPMpcJBO9YcCF11jVEyy:mpjZ+cJBSY9djVEh

    • WarzoneRat, AveMaria

      WarzoneRat is a native RAT developed in C++ with multiple plugins sold as a MaaS.

MITRE ATT&CK Matrix

Tasks