General

  • Target

    f526e1ac3593ecaa49cf5bd96b8752d23a691d7219fc0c920577c8644b543fca

  • Size

    399KB

  • Sample

    240624-lppt3awbqb

  • MD5

    2c6db063db73e091e845a10bbfbbeb8e

  • SHA1

    cab36e13491d04eead0f4d351b88c964734e6928

  • SHA256

    f526e1ac3593ecaa49cf5bd96b8752d23a691d7219fc0c920577c8644b543fca

  • SHA512

    8591390fff896a7fe581337bda31a694a5334912072cd8e270e077809820d814273faa0482baf54ffcdd8599083c6e105461e6c715e55f490db4556f0e154fde

  • SSDEEP

    3072:0TYjLvYIWVPmI006P6cSWWZ6lC03Fexxud8WOrqr0vnoIjYuf9RCX9biBHU+TCEP:0+LhWVOTaW6wd2qciiBXTFeQD4lDGB7

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      f526e1ac3593ecaa49cf5bd96b8752d23a691d7219fc0c920577c8644b543fca

    • Size

      399KB

    • MD5

      2c6db063db73e091e845a10bbfbbeb8e

    • SHA1

      cab36e13491d04eead0f4d351b88c964734e6928

    • SHA256

      f526e1ac3593ecaa49cf5bd96b8752d23a691d7219fc0c920577c8644b543fca

    • SHA512

      8591390fff896a7fe581337bda31a694a5334912072cd8e270e077809820d814273faa0482baf54ffcdd8599083c6e105461e6c715e55f490db4556f0e154fde

    • SSDEEP

      3072:0TYjLvYIWVPmI006P6cSWWZ6lC03Fexxud8WOrqr0vnoIjYuf9RCX9biBHU+TCEP:0+LhWVOTaW6wd2qciiBXTFeQD4lDGB7

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks