General

  • Target

    5657e2064ec6bd2844d0c09af99a7508c0ebdacf6900ca49f047c60796b71815

  • Size

    2.4MB

  • Sample

    240627-2sw1jswdjg

  • MD5

    c513d96fc036f419e607f74248138aa5

  • SHA1

    9ea95ca3b68937483cd23373c72a96a4265017ed

  • SHA256

    5657e2064ec6bd2844d0c09af99a7508c0ebdacf6900ca49f047c60796b71815

  • SHA512

    8129d8fa13e6bd9c07d9ac2ed9f9f8369faf4ab747c55921dd97cdfba8f6ebdae85e67926cf609060df2d659274107c3a66e0a7c3a2d6e4ba6c925bf338d43c9

  • SSDEEP

    49152:KRCZ/D+j5y7GZtOGjczy/hWgdX+dZkWbM65yW+GEOM1GIz0:7JD+jbxczy/hWgakiMXpG8G6

Score
10/10

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      5657e2064ec6bd2844d0c09af99a7508c0ebdacf6900ca49f047c60796b71815

    • Size

      2.4MB

    • MD5

      c513d96fc036f419e607f74248138aa5

    • SHA1

      9ea95ca3b68937483cd23373c72a96a4265017ed

    • SHA256

      5657e2064ec6bd2844d0c09af99a7508c0ebdacf6900ca49f047c60796b71815

    • SHA512

      8129d8fa13e6bd9c07d9ac2ed9f9f8369faf4ab747c55921dd97cdfba8f6ebdae85e67926cf609060df2d659274107c3a66e0a7c3a2d6e4ba6c925bf338d43c9

    • SSDEEP

      49152:KRCZ/D+j5y7GZtOGjczy/hWgdX+dZkWbM65yW+GEOM1GIz0:7JD+jbxczy/hWgakiMXpG8G6

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

2
T1497

Discovery

Query Registry

3
T1012

Virtualization/Sandbox Evasion

2
T1497

System Information Discovery

1
T1082

Tasks