General

  • Target

    gdifuncs.exe

  • Size

    120KB

  • Sample

    240625-ajbvgatakq

  • MD5

    e254e9598ee638c01e5ccc40e604938b

  • SHA1

    541fa2a47f3caaae6aa8f5fbfe4d8aef0001905d

  • SHA256

    4040ad3437e51139819148ed6378828adcfbd924251af39de8bf100a3a476a63

  • SHA512

    92f129a52f2df1f8ed20156e838b79a13baf0cbcdd9c94a5c34f6639c714311f41eb3745fdcc64eac88ce3e6f27d25f9a3250f4ababc630eff7a89802e18b4bb

  • SSDEEP

    1536:DKOz5I1MSx56Hj2UItX85ljPQIe9RoSbGF4q2L6OBIyHwPSYxLanv9QD2i:vteMSMHj/rj1SbGFl2L6CIIw5gv9Qy

Malware Config

Targets

    • Target

      gdifuncs.exe

    • Size

      120KB

    • MD5

      e254e9598ee638c01e5ccc40e604938b

    • SHA1

      541fa2a47f3caaae6aa8f5fbfe4d8aef0001905d

    • SHA256

      4040ad3437e51139819148ed6378828adcfbd924251af39de8bf100a3a476a63

    • SHA512

      92f129a52f2df1f8ed20156e838b79a13baf0cbcdd9c94a5c34f6639c714311f41eb3745fdcc64eac88ce3e6f27d25f9a3250f4ababc630eff7a89802e18b4bb

    • SSDEEP

      1536:DKOz5I1MSx56Hj2UItX85ljPQIe9RoSbGF4q2L6OBIyHwPSYxLanv9QD2i:vteMSMHj/rj1SbGFl2L6CIIw5gv9Qy

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Winlogon Helper DLL

1
T1547.004

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Modify Registry

3
T1112

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

File and Directory Permissions Modification

1
T1222

Discovery

System Information Discovery

1
T1082

Tasks