General

  • Target

    92225a185c38ee81e47b351834fe655afa2846b014f841d0eb66a08568bafafb

  • Size

    2.4MB

  • Sample

    240626-tf9f4svbkn

  • MD5

    0d8f6562cf50b94cb43e6102ff448cae

  • SHA1

    b12a060acc121f6252f77698f0133dd3cd45f5af

  • SHA256

    92225a185c38ee81e47b351834fe655afa2846b014f841d0eb66a08568bafafb

  • SHA512

    9219a06eaff15269b116a95a3bc74d5c858c0be8b5d1a5b2896746fdb48ac46380f98a69b8032d498a4d5470ced35bf247f69dc803d09a4c900d85f59d9d220a

  • SSDEEP

    49152:R8gaKMk3njraj0jv4ExUMn6ZepgOOUerT+f0ua/gBGa9wf4k:GTanKj0jwshY0OXA0ua/goaW

Score
10/10

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      92225a185c38ee81e47b351834fe655afa2846b014f841d0eb66a08568bafafb

    • Size

      2.4MB

    • MD5

      0d8f6562cf50b94cb43e6102ff448cae

    • SHA1

      b12a060acc121f6252f77698f0133dd3cd45f5af

    • SHA256

      92225a185c38ee81e47b351834fe655afa2846b014f841d0eb66a08568bafafb

    • SHA512

      9219a06eaff15269b116a95a3bc74d5c858c0be8b5d1a5b2896746fdb48ac46380f98a69b8032d498a4d5470ced35bf247f69dc803d09a4c900d85f59d9d220a

    • SSDEEP

      49152:R8gaKMk3njraj0jv4ExUMn6ZepgOOUerT+f0ua/gBGa9wf4k:GTanKj0jwshY0OXA0ua/goaW

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

2
T1497

Discovery

Query Registry

3
T1012

Virtualization/Sandbox Evasion

2
T1497

System Information Discovery

1
T1082

Tasks