General

  • Target

    c0436b5f587d904d26f2eadf1b3f64986c51ba4a1d047d2352fa4ad0e70b77c1

  • Size

    894KB

  • Sample

    240627-29neqszerj

  • MD5

    6ffcbcb4845f36ee629ef70f52877c3a

  • SHA1

    9a42a294175aed51ff7935a92994fcc24349ce2b

  • SHA256

    c0436b5f587d904d26f2eadf1b3f64986c51ba4a1d047d2352fa4ad0e70b77c1

  • SHA512

    f5ebcde43406e318be55cd4918f719eeba6dbaf68d9295b74da9c2b025c45d3daa77caf7683e798836a28d0b9d37c48d414f4eae37977b198ea02d0115329acf

  • SSDEEP

    12288:wqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDga4T/:wqDEvCTbMWu7rQYlBQcBiT6rprG8aA/

Score
10/10

Malware Config

Targets

    • Target

      c0436b5f587d904d26f2eadf1b3f64986c51ba4a1d047d2352fa4ad0e70b77c1

    • Size

      894KB

    • MD5

      6ffcbcb4845f36ee629ef70f52877c3a

    • SHA1

      9a42a294175aed51ff7935a92994fcc24349ce2b

    • SHA256

      c0436b5f587d904d26f2eadf1b3f64986c51ba4a1d047d2352fa4ad0e70b77c1

    • SHA512

      f5ebcde43406e318be55cd4918f719eeba6dbaf68d9295b74da9c2b025c45d3daa77caf7683e798836a28d0b9d37c48d414f4eae37977b198ea02d0115329acf

    • SSDEEP

      12288:wqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDga4T/:wqDEvCTbMWu7rQYlBQcBiT6rprG8aA/

    Score
    10/10
    • Detected google phishing page

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks