General

  • Target

    b615008c2cabbc79de198aa92bc72f9bc615bcec1518d88952b40016845553fc

  • Size

    396KB

  • Sample

    240625-szj5ws1ejj

  • MD5

    e6134d93788406050703a9bdaa850c2b

  • SHA1

    64b52b85065bc362e34c91c92ccd65c55bb021e8

  • SHA256

    b615008c2cabbc79de198aa92bc72f9bc615bcec1518d88952b40016845553fc

  • SHA512

    27d26a92f26cdbe9981d5599f112a393f818c8cf1ecbcdd067d36fbf66d9a29cd744a6190ee3ac9241dcd991065d28cfcc5e3905b16e271a2b757bd2ec77e425

  • SSDEEP

    6144:sCL+zUmSYdHtLS4TdX11DKXa9mjB8pPN3:f6zIYzJX11cSmteN

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      b615008c2cabbc79de198aa92bc72f9bc615bcec1518d88952b40016845553fc

    • Size

      396KB

    • MD5

      e6134d93788406050703a9bdaa850c2b

    • SHA1

      64b52b85065bc362e34c91c92ccd65c55bb021e8

    • SHA256

      b615008c2cabbc79de198aa92bc72f9bc615bcec1518d88952b40016845553fc

    • SHA512

      27d26a92f26cdbe9981d5599f112a393f818c8cf1ecbcdd067d36fbf66d9a29cd744a6190ee3ac9241dcd991065d28cfcc5e3905b16e271a2b757bd2ec77e425

    • SSDEEP

      6144:sCL+zUmSYdHtLS4TdX11DKXa9mjB8pPN3:f6zIYzJX11cSmteN

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks