General

  • Target

    c2539e4e2343d9e920fcec5e6d2862b59a9896aa1e69d59be704c73e85a216a4

  • Size

    362KB

  • Sample

    240624-1cwjeasgpd

  • MD5

    ea39533486b749768332d63b826a3ff3

  • SHA1

    295bbf25a53daa0dac340afb5f726f88cf6691c5

  • SHA256

    c2539e4e2343d9e920fcec5e6d2862b59a9896aa1e69d59be704c73e85a216a4

  • SHA512

    37dfdfaeb77bbe8958165430ecfda57a7b6f8373e196f4917bf561b64e592f913a8770e0f1c336e54042290c334879acf46409de7eb068836270bae2bbabc221

  • SSDEEP

    6144:3GLwrOs0T3z7nmjmr9S04mWtChki9mPet:WMrO1zbu2oqWFi

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      c2539e4e2343d9e920fcec5e6d2862b59a9896aa1e69d59be704c73e85a216a4

    • Size

      362KB

    • MD5

      ea39533486b749768332d63b826a3ff3

    • SHA1

      295bbf25a53daa0dac340afb5f726f88cf6691c5

    • SHA256

      c2539e4e2343d9e920fcec5e6d2862b59a9896aa1e69d59be704c73e85a216a4

    • SHA512

      37dfdfaeb77bbe8958165430ecfda57a7b6f8373e196f4917bf561b64e592f913a8770e0f1c336e54042290c334879acf46409de7eb068836270bae2bbabc221

    • SSDEEP

      6144:3GLwrOs0T3z7nmjmr9S04mWtChki9mPet:WMrO1zbu2oqWFi

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks