General

  • Target

    9af00dbe2aecfe5f8cd76a466ee05b9a2d8ec64bc4000d79e21a3a315bcc03c9

  • Size

    310KB

  • Sample

    240627-24k3esxbmc

  • MD5

    4141910717b182a0cbe6e32c527e325f

  • SHA1

    f247bc2dc5c671c74aef338be6f848bbf54e0d44

  • SHA256

    9af00dbe2aecfe5f8cd76a466ee05b9a2d8ec64bc4000d79e21a3a315bcc03c9

  • SHA512

    ae39c610cfe0a548627a7817cef6d87945f03fc559b3fd52a8f843e0499c8d04536880aabb7da90bfbeca6731a69a0763fa989b9f7f18237534798488f5dec2c

  • SSDEEP

    3072:bB2ggCALXBkKgZc5TO4wePyVlv9vZbcx+dxg5bUkBaXa60P:bQgg7LxkKcM/3PyVl9hbndxCUkBs

Malware Config

Extracted

Family

smokeloader

Version

2022

C2

http://movlat.com/tmp/

http://llcbc.org/tmp/

http://lindex24.ru/tmp/

http://qeqei.xyz/tmp/

rc4.i32
rc4.i32

Extracted

Family

smokeloader

Botnet

pub1

Targets

    • Target

      9af00dbe2aecfe5f8cd76a466ee05b9a2d8ec64bc4000d79e21a3a315bcc03c9

    • Size

      310KB

    • MD5

      4141910717b182a0cbe6e32c527e325f

    • SHA1

      f247bc2dc5c671c74aef338be6f848bbf54e0d44

    • SHA256

      9af00dbe2aecfe5f8cd76a466ee05b9a2d8ec64bc4000d79e21a3a315bcc03c9

    • SHA512

      ae39c610cfe0a548627a7817cef6d87945f03fc559b3fd52a8f843e0499c8d04536880aabb7da90bfbeca6731a69a0763fa989b9f7f18237534798488f5dec2c

    • SSDEEP

      3072:bB2ggCALXBkKgZc5TO4wePyVlv9vZbcx+dxg5bUkBaXa60P:bQgg7LxkKcM/3PyVl9hbndxCUkBs

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks