General

  • Target

    ab1e9325f404e2d024b76e1c4ed6a6e362d3388794f45a11872c1a6425d166f1

  • Size

    397KB

  • Sample

    240624-2w4jsswgkd

  • MD5

    91833d11ef41241d667ff14d7af4f4af

  • SHA1

    c08384d818f0f7fe674115d3ffcbecb2ab66ac2d

  • SHA256

    ab1e9325f404e2d024b76e1c4ed6a6e362d3388794f45a11872c1a6425d166f1

  • SHA512

    1678314b392fe656ea18166088846dca4b3be8a83e7705e7677a15f64fd6fedb02db77f347392ecef817a0f9d284e818c70298917c1f6a4d16983c1a3f613a39

  • SSDEEP

    6144:7d0QL5SADahYY2lBd9rV5BoRi8AT59bhgBrQ6lz1Y7isi:xVdSASO/lGRX2bhgNu7i

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      ab1e9325f404e2d024b76e1c4ed6a6e362d3388794f45a11872c1a6425d166f1

    • Size

      397KB

    • MD5

      91833d11ef41241d667ff14d7af4f4af

    • SHA1

      c08384d818f0f7fe674115d3ffcbecb2ab66ac2d

    • SHA256

      ab1e9325f404e2d024b76e1c4ed6a6e362d3388794f45a11872c1a6425d166f1

    • SHA512

      1678314b392fe656ea18166088846dca4b3be8a83e7705e7677a15f64fd6fedb02db77f347392ecef817a0f9d284e818c70298917c1f6a4d16983c1a3f613a39

    • SSDEEP

      6144:7d0QL5SADahYY2lBd9rV5BoRi8AT59bhgBrQ6lz1Y7isi:xVdSASO/lGRX2bhgNu7i

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks