General

  • Target

    d19591949c0249ab0441334064937595ac8d141da5a892b8c55b19f91198c578

  • Size

    176KB

  • Sample

    240625-c8q2sszejn

  • MD5

    0a8ee3d471f71ed40241d24b8d1932af

  • SHA1

    79c7af261deeedb13f087de44bb7765336821314

  • SHA256

    d19591949c0249ab0441334064937595ac8d141da5a892b8c55b19f91198c578

  • SHA512

    d46fb57014e53f60162c7290ab713cc19d4bd360547605d5359ecb20f168ff1c53ca53c9b2e9c9a9f9007b05ca02f8510214236dc43b05cb520052e738d2afc0

  • SSDEEP

    3072:5N7iMf3nwVQywGvFt3II7A1lJJyjGbhCI6kiNqzuF+8OqtOAg0Fuj0BrVKZaD:5N7iMfXwVQibIa6bTCIbiNmpAOsKZaD

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

185.172.128.69

Attributes
  • url_path

    /advdlc.php

Targets

    • Target

      d19591949c0249ab0441334064937595ac8d141da5a892b8c55b19f91198c578

    • Size

      176KB

    • MD5

      0a8ee3d471f71ed40241d24b8d1932af

    • SHA1

      79c7af261deeedb13f087de44bb7765336821314

    • SHA256

      d19591949c0249ab0441334064937595ac8d141da5a892b8c55b19f91198c578

    • SHA512

      d46fb57014e53f60162c7290ab713cc19d4bd360547605d5359ecb20f168ff1c53ca53c9b2e9c9a9f9007b05ca02f8510214236dc43b05cb520052e738d2afc0

    • SSDEEP

      3072:5N7iMf3nwVQywGvFt3II7A1lJJyjGbhCI6kiNqzuF+8OqtOAg0Fuj0BrVKZaD:5N7iMfXwVQibIa6bTCIbiNmpAOsKZaD

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks