General

  • Target

    MonsterHack.rar

  • Size

    1.6MB

  • Sample

    240623-nzv5yatbln

  • MD5

    c3e9b5d03207fac9cfbc67244749cca1

  • SHA1

    d92825d94a89255859e31bd7393bc833056e3b13

  • SHA256

    6fad65e07016e5e124331e2fa805da27ffd2498fc4b3a622d1f5c8ca5fd72a00

  • SHA512

    0573f3587af44f9996eef8181ee3a6b75e9c6baeb9d9623d3b8a11ff8edd30bda7a0c663e90b620317f05b5e887d5e52deeccf53eabb33284308596360f9c9d8

  • SSDEEP

    24576:JwqX8NWpU2VwBFaXFhX+Pch8VAcAgH2ixrv7LuwhKZWSgJ7I2xKFFbIwzxt/J9P:XBKU2FaXFdH8VhAK2c7LBH9FEFblrBF

Malware Config

Targets

    • Target

      MonsterHack.exe

    • Size

      4.0MB

    • MD5

      6efea760737c914276321712b7c5faf0

    • SHA1

      cac227707c574deba24c71c85e64e0da1e246b11

    • SHA256

      6952e0e1fc7847b46473a9f22ba352a06623f966e08bb6f79a8b189a117e1510

    • SHA512

      f60077d79a205a78ca86dbd32072604298e2df14dbbc96c94561765289aaeb79123b5fe747e9dcda8289682c57805b9449c67f21f10f4b2453abf09b0ac88561

    • SSDEEP

      49152:5NDFFPJu8fBsVE6ij+RNg+UKpBvtqB3m1RC3:vzP88fBsnZTgOtqB3m1RC3

    • LoaderBot

      LoaderBot is a loader written in .NET downloading and executing miners.

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • LoaderBot executable

    • XMRig Miner payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Drops startup file

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

System Information Discovery

4
T1082

Peripheral Device Discovery

1
T1120

Tasks