General

  • Target

    c7202bad6ca8ca0b8444039d387441223cc89867cabfd8b8eac02dc8c0c0a1a3

  • Size

    392KB

  • Sample

    240625-ty3raatcln

  • MD5

    b2d4091da12d2f8a9636cdd58df58e9d

  • SHA1

    b5626149f09ae8c263c78c7794b4c669f4f67aaa

  • SHA256

    c7202bad6ca8ca0b8444039d387441223cc89867cabfd8b8eac02dc8c0c0a1a3

  • SHA512

    6769e319e58c75b0313b834ab5150fdb8ab3f0980a5684be5569a48de0484cb61d1cbebe72509a509978f6fb7cc09de072e4d436f0ac6eb4db21da94f0f27604

  • SSDEEP

    6144:l+LNRunVy03asWAtkSFL2MDGVfJIxNF8FEFBN3:l+SnVyiaOt3FLUVaGEFBN

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

5.42.64.56

185.172.128.69

Targets

    • Target

      c7202bad6ca8ca0b8444039d387441223cc89867cabfd8b8eac02dc8c0c0a1a3

    • Size

      392KB

    • MD5

      b2d4091da12d2f8a9636cdd58df58e9d

    • SHA1

      b5626149f09ae8c263c78c7794b4c669f4f67aaa

    • SHA256

      c7202bad6ca8ca0b8444039d387441223cc89867cabfd8b8eac02dc8c0c0a1a3

    • SHA512

      6769e319e58c75b0313b834ab5150fdb8ab3f0980a5684be5569a48de0484cb61d1cbebe72509a509978f6fb7cc09de072e4d436f0ac6eb4db21da94f0f27604

    • SSDEEP

      6144:l+LNRunVy03asWAtkSFL2MDGVfJIxNF8FEFBN3:l+SnVyiaOt3FLUVaGEFBN

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks