General

  • Target

    2024-06-26_0078191a294f1b63c7c35cd7f8ecc123_bkransomware_karagany

  • Size

    732KB

  • Sample

    240626-1kwjdavhpc

  • MD5

    0078191a294f1b63c7c35cd7f8ecc123

  • SHA1

    f66ac199514df53ce39534206a475217901aba7e

  • SHA256

    225767d5cfcbfb36b9ae1f8b5e424495fa8cac8a20361bf5f640e48f06258ef4

  • SHA512

    b26419bc4dfb1058916b41ffb9afd69d52381196dadb47ea450eec16a06a259dad369d06263de5793ad7e7b90017b224786c5152c0963d59958ef210e42f9cfd

  • SSDEEP

    6144:yBb/GhISjsUpwWx7ko0dvmfMaZaocS427zkXQj3805rSj15jBvp9HxawFH4yeK1a:yBLGO0oWp6ZmEOazhsyQt5r

Malware Config

Targets

    • Target

      2024-06-26_0078191a294f1b63c7c35cd7f8ecc123_bkransomware_karagany

    • Size

      732KB

    • MD5

      0078191a294f1b63c7c35cd7f8ecc123

    • SHA1

      f66ac199514df53ce39534206a475217901aba7e

    • SHA256

      225767d5cfcbfb36b9ae1f8b5e424495fa8cac8a20361bf5f640e48f06258ef4

    • SHA512

      b26419bc4dfb1058916b41ffb9afd69d52381196dadb47ea450eec16a06a259dad369d06263de5793ad7e7b90017b224786c5152c0963d59958ef210e42f9cfd

    • SSDEEP

      6144:yBb/GhISjsUpwWx7ko0dvmfMaZaocS427zkXQj3805rSj15jBvp9HxawFH4yeK1a:yBLGO0oWp6ZmEOazhsyQt5r

    • GandCrab payload

    • Gandcrab

      Gandcrab is a Trojan horse that encrypts files on a computer.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks