General

  • Target

    4efdae419cd6ff29897612e8120c30cc78d947ca0bfec23646d6208b3758c962

  • Size

    3.3MB

  • Sample

    240627-2rz1tawcna

  • MD5

    1c8509719a1c72db8addc669dd4c68bd

  • SHA1

    6d85832317d36a4f2190768fa8f3c141a3ac6d1b

  • SHA256

    4efdae419cd6ff29897612e8120c30cc78d947ca0bfec23646d6208b3758c962

  • SHA512

    bded8248e35fbe21f6e3e00d3c3a411e821c0b4d8c4f4dcea48a8fa4bf6fe4e204feca15ff0f21fdf8ec1bf071dc183d65bf2c32df9e8ed65b04e45e614ef918

  • SSDEEP

    98304:FyLQ961AQnMJXYa7zi+BfmYXha6Bm08CllKlU:r9EA+MJXvi+BM6s07llKi

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      4efdae419cd6ff29897612e8120c30cc78d947ca0bfec23646d6208b3758c962

    • Size

      3.3MB

    • MD5

      1c8509719a1c72db8addc669dd4c68bd

    • SHA1

      6d85832317d36a4f2190768fa8f3c141a3ac6d1b

    • SHA256

      4efdae419cd6ff29897612e8120c30cc78d947ca0bfec23646d6208b3758c962

    • SHA512

      bded8248e35fbe21f6e3e00d3c3a411e821c0b4d8c4f4dcea48a8fa4bf6fe4e204feca15ff0f21fdf8ec1bf071dc183d65bf2c32df9e8ed65b04e45e614ef918

    • SSDEEP

      98304:FyLQ961AQnMJXYa7zi+BfmYXha6Bm08CllKlU:r9EA+MJXvi+BM6s07llKi

    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks