General

  • Target

    6b2011da06b3eff03a2045e630d59a04a351dbfe10cccd83915f6d8bcc5d99c6

  • Size

    894KB

  • Sample

    240627-2wrv1ayflm

  • MD5

    6c03b44b9065c6384984f2662a45a8e5

  • SHA1

    27e33fc44075f6704ddc09a8d6f6360e0a6391cd

  • SHA256

    6b2011da06b3eff03a2045e630d59a04a351dbfe10cccd83915f6d8bcc5d99c6

  • SHA512

    c855d8da39d532b8233f4564faaceb30e651518cb896fbfb2963fe9e23eec5d1b7275d0c2a4b7d187952d8a000aabb128f875a3af03a1439b3b8a8861e669c31

  • SSDEEP

    12288:cqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDga4T3:cqDEvCTbMWu7rQYlBQcBiT6rprG8aA3

Score
10/10

Malware Config

Targets

    • Target

      6b2011da06b3eff03a2045e630d59a04a351dbfe10cccd83915f6d8bcc5d99c6

    • Size

      894KB

    • MD5

      6c03b44b9065c6384984f2662a45a8e5

    • SHA1

      27e33fc44075f6704ddc09a8d6f6360e0a6391cd

    • SHA256

      6b2011da06b3eff03a2045e630d59a04a351dbfe10cccd83915f6d8bcc5d99c6

    • SHA512

      c855d8da39d532b8233f4564faaceb30e651518cb896fbfb2963fe9e23eec5d1b7275d0c2a4b7d187952d8a000aabb128f875a3af03a1439b3b8a8861e669c31

    • SSDEEP

      12288:cqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDga4T3:cqDEvCTbMWu7rQYlBQcBiT6rprG8aA3

    Score
    10/10
    • Detected google phishing page

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks