General

  • Target

    04a6c2a586e9c15bd4a762e0f969919bf21751ab4751b0b49e592302a3013580

  • Size

    399KB

  • Sample

    240624-psth7swbqr

  • MD5

    bc60d66165eb3d4a2a4ed565399bf647

  • SHA1

    9035f19c80fd1028ca6a22cee861f531b96d9eea

  • SHA256

    04a6c2a586e9c15bd4a762e0f969919bf21751ab4751b0b49e592302a3013580

  • SHA512

    2b05dddd5b34856118793df31db3626c173dd2efaa8045975b541d39c4647d6d36f2ec916fa6a284e85211b5f4fc394392402e1fee040774fba298a08c2636f8

  • SSDEEP

    6144:5DL4WFyObRD6wIH4XEM5zi2mEzRerEaMBA2k:Z0ayO1DlIY0YBz

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      04a6c2a586e9c15bd4a762e0f969919bf21751ab4751b0b49e592302a3013580

    • Size

      399KB

    • MD5

      bc60d66165eb3d4a2a4ed565399bf647

    • SHA1

      9035f19c80fd1028ca6a22cee861f531b96d9eea

    • SHA256

      04a6c2a586e9c15bd4a762e0f969919bf21751ab4751b0b49e592302a3013580

    • SHA512

      2b05dddd5b34856118793df31db3626c173dd2efaa8045975b541d39c4647d6d36f2ec916fa6a284e85211b5f4fc394392402e1fee040774fba298a08c2636f8

    • SSDEEP

      6144:5DL4WFyObRD6wIH4XEM5zi2mEzRerEaMBA2k:Z0ayO1DlIY0YBz

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks