General

  • Target

    ed89d7882eb5642f484531e5213aad32735d46cb172ce3ec34d5deae2f840dd3

  • Size

    3.2MB

  • Sample

    240627-3g6laa1ckr

  • MD5

    fe182843b69a49502f78990a486e2b61

  • SHA1

    9a9765228de800dd776c29f6e6f3426207dddc01

  • SHA256

    ed89d7882eb5642f484531e5213aad32735d46cb172ce3ec34d5deae2f840dd3

  • SHA512

    d0c301fe2e82fa73ecaa358d43f80ecc008fc6562a38f616a7be2507824d42c236ef461a592f4afddffddea75588937c9b9fcc4096acb9814e810ca9ea4058c3

  • SSDEEP

    98304:2TsJn5Knwrb1/+Ae6ZATCs750POPrwFtktHY4FDT7C:24qw51ZATn75RT20BC

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      ed89d7882eb5642f484531e5213aad32735d46cb172ce3ec34d5deae2f840dd3

    • Size

      3.2MB

    • MD5

      fe182843b69a49502f78990a486e2b61

    • SHA1

      9a9765228de800dd776c29f6e6f3426207dddc01

    • SHA256

      ed89d7882eb5642f484531e5213aad32735d46cb172ce3ec34d5deae2f840dd3

    • SHA512

      d0c301fe2e82fa73ecaa358d43f80ecc008fc6562a38f616a7be2507824d42c236ef461a592f4afddffddea75588937c9b9fcc4096acb9814e810ca9ea4058c3

    • SSDEEP

      98304:2TsJn5Knwrb1/+Ae6ZATCs750POPrwFtktHY4FDT7C:24qw51ZATn75RT20BC

    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks