General

  • Target

    aea4ec8d33f833ecb9062718874457bf3fe2b0b1fe022fd708818dd5aaa99d8a

  • Size

    392KB

  • Sample

    240625-t6aqga1dqb

  • MD5

    f67c28684ee88052af7968dcf2b09b32

  • SHA1

    b3ca98e8a5eb5fd5c826200ec5b6c50ee5f15881

  • SHA256

    aea4ec8d33f833ecb9062718874457bf3fe2b0b1fe022fd708818dd5aaa99d8a

  • SHA512

    86ff0539ea26e3a8d18815ecd974a9d3b8558bdae2d08fc6553f936036c52a3d22a1b0409fbca7b161305016fe68675e5185a5171aaa3a3e470e757c874684f2

  • SSDEEP

    6144:7sLfTFKo6fMbSIxFKRhPOGDtjHHS1CP8fZN3:oLTt6fMYPRSAPmN

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      aea4ec8d33f833ecb9062718874457bf3fe2b0b1fe022fd708818dd5aaa99d8a

    • Size

      392KB

    • MD5

      f67c28684ee88052af7968dcf2b09b32

    • SHA1

      b3ca98e8a5eb5fd5c826200ec5b6c50ee5f15881

    • SHA256

      aea4ec8d33f833ecb9062718874457bf3fe2b0b1fe022fd708818dd5aaa99d8a

    • SHA512

      86ff0539ea26e3a8d18815ecd974a9d3b8558bdae2d08fc6553f936036c52a3d22a1b0409fbca7b161305016fe68675e5185a5171aaa3a3e470e757c874684f2

    • SSDEEP

      6144:7sLfTFKo6fMbSIxFKRhPOGDtjHHS1CP8fZN3:oLTt6fMYPRSAPmN

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks