General

  • Target

    2024-06-27_6d50275da10f1aceaff97fd152fa6cbd_gandcrab

  • Size

    145KB

  • Sample

    240627-g82krayhmm

  • MD5

    6d50275da10f1aceaff97fd152fa6cbd

  • SHA1

    049ede3c62240fc6367db5f592fad519f97e31a5

  • SHA256

    d94662e1ed32a9b03607a3038091cdad1d338e9bfe1e09717a6698b70f3b6aed

  • SHA512

    e799b66a9a5919494bde210acf820b87d6591c5f0aa3bf95c23d171bdd428cad67dfb6435a38acadeb7af0ed154c6c37629a35133695df9e5abf0cb5cce4acd6

  • SSDEEP

    3072:0YHVHd2NCMqqDL2/mr3IdE8we0Avu5r++ygLIaagvdCjRv9OtN:0yOqqDL64vdGREz

Malware Config

Targets

    • Target

      2024-06-27_6d50275da10f1aceaff97fd152fa6cbd_gandcrab

    • Size

      145KB

    • MD5

      6d50275da10f1aceaff97fd152fa6cbd

    • SHA1

      049ede3c62240fc6367db5f592fad519f97e31a5

    • SHA256

      d94662e1ed32a9b03607a3038091cdad1d338e9bfe1e09717a6698b70f3b6aed

    • SHA512

      e799b66a9a5919494bde210acf820b87d6591c5f0aa3bf95c23d171bdd428cad67dfb6435a38acadeb7af0ed154c6c37629a35133695df9e5abf0cb5cce4acd6

    • SSDEEP

      3072:0YHVHd2NCMqqDL2/mr3IdE8we0Avu5r++ygLIaagvdCjRv9OtN:0yOqqDL64vdGREz

    • GandCrab payload

    • Gandcrab

      Gandcrab is a Trojan horse that encrypts files on a computer.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks