General

  • Target

    3dacbd51724d7267ded7bae261b0f9fe20dc878ca9c9f1534f4d7d7f767205c0

  • Size

    399KB

  • Sample

    240624-ydal8azbpg

  • MD5

    dfde0091e827eec65d2101c001fbaec4

  • SHA1

    c5bcc17c658945eb4b3dd2ae60fe76d8a7ec4306

  • SHA256

    3dacbd51724d7267ded7bae261b0f9fe20dc878ca9c9f1534f4d7d7f767205c0

  • SHA512

    4653a094f6887a52ade054b1a6f614ac3d6070fe356c8fb9955ee1d4577665bd1b98d7f96411ca7bec335c236620ddbabbd5d3e46ac7341443b29ed18cd9c6b5

  • SSDEEP

    6144:P69LzWNaU0fMRD4OngmKIp/bdQeAXGz7r+xXhxX:E3UaU14egcppKiG/

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      3dacbd51724d7267ded7bae261b0f9fe20dc878ca9c9f1534f4d7d7f767205c0

    • Size

      399KB

    • MD5

      dfde0091e827eec65d2101c001fbaec4

    • SHA1

      c5bcc17c658945eb4b3dd2ae60fe76d8a7ec4306

    • SHA256

      3dacbd51724d7267ded7bae261b0f9fe20dc878ca9c9f1534f4d7d7f767205c0

    • SHA512

      4653a094f6887a52ade054b1a6f614ac3d6070fe356c8fb9955ee1d4577665bd1b98d7f96411ca7bec335c236620ddbabbd5d3e46ac7341443b29ed18cd9c6b5

    • SSDEEP

      6144:P69LzWNaU0fMRD4OngmKIp/bdQeAXGz7r+xXhxX:E3UaU14egcppKiG/

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks