General

  • Target

    9a4c96b227213b7049f851572487d42c994220bbf584f631bf347a507b684c1a

  • Size

    4.8MB

  • Sample

    240623-ljzgba1gml

  • MD5

    1fecbc51b5620e578c48a12ebeb19bc2

  • SHA1

    94fe551f4fb3ff76a0be99a962dc20fc2656453e

  • SHA256

    9a4c96b227213b7049f851572487d42c994220bbf584f631bf347a507b684c1a

  • SHA512

    ede6f39946562e253fcafe225292db32ba30f9476557304ae1769830e3a46c660920c304ca42d52544411e41acfc1bf206c829c98d61948cb595b1fa0105e2d7

  • SSDEEP

    98304:6qwWqwfM8jZlts7Dnfg+u5NIg1GbnBH9Ltl4NFA0kA8X1KpWQMg:6qwWqw0v7DnZu5NnobnDtl4TjZ8X1/Qf

Malware Config

Extracted

Family

loaderbot

C2

https://cv99160.tw1.ru/cmd.php

Targets

    • Target

      9a4c96b227213b7049f851572487d42c994220bbf584f631bf347a507b684c1a

    • Size

      4.8MB

    • MD5

      1fecbc51b5620e578c48a12ebeb19bc2

    • SHA1

      94fe551f4fb3ff76a0be99a962dc20fc2656453e

    • SHA256

      9a4c96b227213b7049f851572487d42c994220bbf584f631bf347a507b684c1a

    • SHA512

      ede6f39946562e253fcafe225292db32ba30f9476557304ae1769830e3a46c660920c304ca42d52544411e41acfc1bf206c829c98d61948cb595b1fa0105e2d7

    • SSDEEP

      98304:6qwWqwfM8jZlts7Dnfg+u5NIg1GbnBH9Ltl4NFA0kA8X1KpWQMg:6qwWqw0v7DnZu5NnobnDtl4TjZ8X1/Qf

    • LoaderBot

      LoaderBot is a loader written in .NET downloading and executing miners.

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • LoaderBot executable

    • XMRig Miner payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks