General

  • Target

    26f7c96fb81113356d510e0c38defb5ccc4d60d1c7f446cdd7468b7fdee65537

  • Size

    3.4MB

  • Sample

    240627-2lh54svgnc

  • MD5

    513691baacc2aa5defb155d6bf3f12dd

  • SHA1

    c78c22ec6cfd744563df03ae40501a5d69f7a7c6

  • SHA256

    26f7c96fb81113356d510e0c38defb5ccc4d60d1c7f446cdd7468b7fdee65537

  • SHA512

    2ca4f1eb328d082cc72c9892e65766647fa80e040be635c978f4c160a2239086e39269fa777c70e2fc52cac00c0361b3e4cc41610bf61e55fd243934b763b7cd

  • SSDEEP

    98304:dS/tQkrQBB6kARtvvn3JO+yamxBmnkrxWRZ:IrYA3P3cGmykS

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      26f7c96fb81113356d510e0c38defb5ccc4d60d1c7f446cdd7468b7fdee65537

    • Size

      3.4MB

    • MD5

      513691baacc2aa5defb155d6bf3f12dd

    • SHA1

      c78c22ec6cfd744563df03ae40501a5d69f7a7c6

    • SHA256

      26f7c96fb81113356d510e0c38defb5ccc4d60d1c7f446cdd7468b7fdee65537

    • SHA512

      2ca4f1eb328d082cc72c9892e65766647fa80e040be635c978f4c160a2239086e39269fa777c70e2fc52cac00c0361b3e4cc41610bf61e55fd243934b763b7cd

    • SSDEEP

      98304:dS/tQkrQBB6kARtvvn3JO+yamxBmnkrxWRZ:IrYA3P3cGmykS

    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks