General

  • Target

    NOIDEA.jar

  • Size

    2.3MB

  • Sample

    240625-qlrlpsvflq

  • MD5

    24a7587cb61f673472bdb49c370959d5

  • SHA1

    22e57c86d7a81882e61030cff94d151eba13bd2f

  • SHA256

    a44882003aae3c833f7540e12b9db89240b5f02669949e72cdc600485135e511

  • SHA512

    7c6756b4d6fce3ebfccf110364f70f3c3b7d14acc9d9cbf6d56a61075dd80c2bc8ce531caeca0f9d60075627ba1e9fd957a513af241f0721f80ae1eff87a005a

  • SSDEEP

    49152:FIQEEbC3k2EeKu3ThgcUe5BFYtACdY+ZJ1uI4eNSjJaa:FJEXk224ThgcUeYsCTuIkjJL

Malware Config

Targets

    • Target

      NOIDEA.jar

    • Size

      2.3MB

    • MD5

      24a7587cb61f673472bdb49c370959d5

    • SHA1

      22e57c86d7a81882e61030cff94d151eba13bd2f

    • SHA256

      a44882003aae3c833f7540e12b9db89240b5f02669949e72cdc600485135e511

    • SHA512

      7c6756b4d6fce3ebfccf110364f70f3c3b7d14acc9d9cbf6d56a61075dd80c2bc8ce531caeca0f9d60075627ba1e9fd957a513af241f0721f80ae1eff87a005a

    • SSDEEP

      49152:FIQEEbC3k2EeKu3ThgcUe5BFYtACdY+ZJ1uI4eNSjJaa:FJEXk224ThgcUeYsCTuIkjJL

    • Modifies file permissions

    • Adds Run key to start application

    • Legitimate hosting services abused for malware hosting/C2

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

File and Directory Permissions Modification

1
T1222

Modify Registry

1
T1112

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Command and Control

Web Service

1
T1102

Tasks