General

  • Target

    e886c9dd1678f356230fc77d34136860aa3316a6f802c1045fdac119fd614d12

  • Size

    3.4MB

  • Sample

    240627-3glwwaybkg

  • MD5

    25b8ee5045c6c102ea319db6662204fe

  • SHA1

    5f3a1e5cf988f7a9942382f90d7adcca8b3c77db

  • SHA256

    e886c9dd1678f356230fc77d34136860aa3316a6f802c1045fdac119fd614d12

  • SHA512

    75da6a70dec3bacade9114dd22e4a130220ad510770114b3eda84e93200944d504317132a8970dfa0018e5e511681ec65c013372bba86b360052c398fd6347e9

  • SSDEEP

    98304:6B8FI7GDJy8eQzeWY7P5ta8+m8JADB7t2oaMqwG:zDoQCVzaV0Vt2o+

Malware Config

Extracted

Family

risepro

C2

77.91.77.66:58709

Targets

    • Target

      e886c9dd1678f356230fc77d34136860aa3316a6f802c1045fdac119fd614d12

    • Size

      3.4MB

    • MD5

      25b8ee5045c6c102ea319db6662204fe

    • SHA1

      5f3a1e5cf988f7a9942382f90d7adcca8b3c77db

    • SHA256

      e886c9dd1678f356230fc77d34136860aa3316a6f802c1045fdac119fd614d12

    • SHA512

      75da6a70dec3bacade9114dd22e4a130220ad510770114b3eda84e93200944d504317132a8970dfa0018e5e511681ec65c013372bba86b360052c398fd6347e9

    • SSDEEP

      98304:6B8FI7GDJy8eQzeWY7P5ta8+m8JADB7t2oaMqwG:zDoQCVzaV0Vt2o+

    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks