Resubmissions

27-06-2024 00:44

240627-a3xahswdlr 10

27-06-2024 00:40

240627-az8t5swbrn 6

General

  • Target

    setup.msi

  • Size

    25.2MB

  • Sample

    240627-az8t5swbrn

  • MD5

    3d87a0e5517c9a8fc4adde50bafe7c76

  • SHA1

    a1ba3b688dcb9b17ed1d430f3032e2884a0565e4

  • SHA256

    49dc002fa1a0a1e33621a7d9340fb7bd0ac8b9834fc5958823d1f2bed6fa5956

  • SHA512

    ebadfdc465dc5c32c854931a9f8712320cfc3752e04b3fec56a1b103c6f225c1de0c6892b1cd90b362f56d38685b8d5851e2cbefdf3291f8389b5cea2e337042

  • SSDEEP

    393216:f+KUUMVzPuPA9BA/UODO0HAAqC+7Rw+lK2WhAS7KdROb7xmq7IrWowIpUDV5:f+YMVD9cECbq+QWhASOdM3N7gTwx

Malware Config

Targets

    • Target

      setup.msi

    • Size

      25.2MB

    • MD5

      3d87a0e5517c9a8fc4adde50bafe7c76

    • SHA1

      a1ba3b688dcb9b17ed1d430f3032e2884a0565e4

    • SHA256

      49dc002fa1a0a1e33621a7d9340fb7bd0ac8b9834fc5958823d1f2bed6fa5956

    • SHA512

      ebadfdc465dc5c32c854931a9f8712320cfc3752e04b3fec56a1b103c6f225c1de0c6892b1cd90b362f56d38685b8d5851e2cbefdf3291f8389b5cea2e337042

    • SSDEEP

      393216:f+KUUMVzPuPA9BA/UODO0HAAqC+7Rw+lK2WhAS7KdROb7xmq7IrWowIpUDV5:f+YMVD9cECbq+QWhASOdM3N7gTwx

    • Blocklisted process makes network request

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Privilege Escalation

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks