General

  • Target

    8e75eb4be933cc3d1312708a7a3ad1521f03b3aba48a459c36af214d5fdc1b8d

  • Size

    396KB

  • Sample

    240625-mfd7mstgnh

  • MD5

    a4da23bee8a2d83eb6391d00e38a4f70

  • SHA1

    cc2b2ef75a0027973597d1cf5730e5069710025e

  • SHA256

    8e75eb4be933cc3d1312708a7a3ad1521f03b3aba48a459c36af214d5fdc1b8d

  • SHA512

    367b3f972b46dd33e4545aa810ad9b21de409e5097d68906223db15f9fc1239dc3b817f141d45a50b55639a7c276465847b8349faa8a93745d215840ca56cde2

  • SSDEEP

    6144:t1LsasK9U1f2shXUA+hnruHypBWMtJj9Qjo8UNH:DIaBe1PXU1nSHYBWyN5TN

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      8e75eb4be933cc3d1312708a7a3ad1521f03b3aba48a459c36af214d5fdc1b8d

    • Size

      396KB

    • MD5

      a4da23bee8a2d83eb6391d00e38a4f70

    • SHA1

      cc2b2ef75a0027973597d1cf5730e5069710025e

    • SHA256

      8e75eb4be933cc3d1312708a7a3ad1521f03b3aba48a459c36af214d5fdc1b8d

    • SHA512

      367b3f972b46dd33e4545aa810ad9b21de409e5097d68906223db15f9fc1239dc3b817f141d45a50b55639a7c276465847b8349faa8a93745d215840ca56cde2

    • SSDEEP

      6144:t1LsasK9U1f2shXUA+hnruHypBWMtJj9Qjo8UNH:DIaBe1PXU1nSHYBWyN5TN

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks