General

  • Target

    eea2dad90e273ea446be65029242297a1d207b862ffc71d5f7a6ab6369c38303

  • Size

    366KB

  • Sample

    240623-yp89xstdrn

  • MD5

    052e588f5cc2565c811934b31aa73561

  • SHA1

    8585564b29c27f657b71708a908579a9c6d72903

  • SHA256

    eea2dad90e273ea446be65029242297a1d207b862ffc71d5f7a6ab6369c38303

  • SHA512

    41d7b56356b1aab4ead2ec6b56816747db7b93dd0bd5c6aedd5261ebe4ad3235cbef1c668ccc1046ae08a0a843031912f029ed8923d32820d7ec56ceefd7a963

  • SSDEEP

    3072:b05XyFNxLxJ2GXr+zKFMdReJLbTWkv+YKFMrrqeztExga48Id36UeG4K:bAyFNxPj7+zKFQReN6kRaPU

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      eea2dad90e273ea446be65029242297a1d207b862ffc71d5f7a6ab6369c38303

    • Size

      366KB

    • MD5

      052e588f5cc2565c811934b31aa73561

    • SHA1

      8585564b29c27f657b71708a908579a9c6d72903

    • SHA256

      eea2dad90e273ea446be65029242297a1d207b862ffc71d5f7a6ab6369c38303

    • SHA512

      41d7b56356b1aab4ead2ec6b56816747db7b93dd0bd5c6aedd5261ebe4ad3235cbef1c668ccc1046ae08a0a843031912f029ed8923d32820d7ec56ceefd7a963

    • SSDEEP

      3072:b05XyFNxLxJ2GXr+zKFMdReJLbTWkv+YKFMrrqeztExga48Id36UeG4K:bAyFNxPj7+zKFQReN6kRaPU

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks