General

  • Target

    8c19ac5a1cb0a5f7c9ffd573fb777b2333ac7ad62d23a4a710fa2b8c3efd73f5

  • Size

    250KB

  • Sample

    240624-3pjrgs1hjq

  • MD5

    70b60666cb028263dceb5203156a850d

  • SHA1

    a1beabd238c4abfe00976a62f2f494298c7a5e5a

  • SHA256

    8c19ac5a1cb0a5f7c9ffd573fb777b2333ac7ad62d23a4a710fa2b8c3efd73f5

  • SHA512

    e828845556d8ef669b558a7bb60e515e910887336a96dcf9ca077947988f6da841c3b2baa18609032080adc357bb180763cc745d79013db9c2a3bb710dd39fb8

  • SSDEEP

    3072:Y7USOxqXCI5HeDn8TlmAYfwDHT776eLfEKdLiovxTXIiPcXS0XYMI3V1nF23M/V:D0CI5HfmlfUH/ffF7IiUPXgVVF23M

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

185.172.128.69

Attributes
  • url_path

    /advdlc.php

Targets

    • Target

      8c19ac5a1cb0a5f7c9ffd573fb777b2333ac7ad62d23a4a710fa2b8c3efd73f5

    • Size

      250KB

    • MD5

      70b60666cb028263dceb5203156a850d

    • SHA1

      a1beabd238c4abfe00976a62f2f494298c7a5e5a

    • SHA256

      8c19ac5a1cb0a5f7c9ffd573fb777b2333ac7ad62d23a4a710fa2b8c3efd73f5

    • SHA512

      e828845556d8ef669b558a7bb60e515e910887336a96dcf9ca077947988f6da841c3b2baa18609032080adc357bb180763cc745d79013db9c2a3bb710dd39fb8

    • SSDEEP

      3072:Y7USOxqXCI5HeDn8TlmAYfwDHT776eLfEKdLiovxTXIiPcXS0XYMI3V1nF23M/V:D0CI5HfmlfUH/ffF7IiUPXgVVF23M

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks