General

  • Target

    2ac4a52e9f94b9e517e14b749811fa98.exe

  • Size

    311KB

  • Sample

    240627-hw267a1ajj

  • MD5

    2ac4a52e9f94b9e517e14b749811fa98

  • SHA1

    8a693552de74d98bc67daf5216241718a93b4d83

  • SHA256

    7024e2012b8c0acec20f70d4dda73ea9a67b234535bf7f27eb68c6dc8338ccab

  • SHA512

    e2bd2115736ae2fa70decc5cdce56e3deb37bdb6732769a54d466b807b2bb17ad0de3f5f3148800a9c2e64006baa403e9625d9495e27f3b054ebdd69170a37b4

  • SSDEEP

    3072:oqY/LzCkS/0tmJcnJvn+rnFTilV27LQSHq5T9K8N80gP:oqqLmkScmwv+LVOVMkwQ9KO

Malware Config

Extracted

Family

smokeloader

Botnet

pub1

Extracted

Family

smokeloader

Version

2022

C2

http://movlat.com/tmp/

http://llcbc.org/tmp/

http://lindex24.ru/tmp/

http://qeqei.xyz/tmp/

rc4.i32
rc4.i32

Targets

    • Target

      2ac4a52e9f94b9e517e14b749811fa98.exe

    • Size

      311KB

    • MD5

      2ac4a52e9f94b9e517e14b749811fa98

    • SHA1

      8a693552de74d98bc67daf5216241718a93b4d83

    • SHA256

      7024e2012b8c0acec20f70d4dda73ea9a67b234535bf7f27eb68c6dc8338ccab

    • SHA512

      e2bd2115736ae2fa70decc5cdce56e3deb37bdb6732769a54d466b807b2bb17ad0de3f5f3148800a9c2e64006baa403e9625d9495e27f3b054ebdd69170a37b4

    • SSDEEP

      3072:oqY/LzCkS/0tmJcnJvn+rnFTilV27LQSHq5T9K8N80gP:oqqLmkScmwv+LVOVMkwQ9KO

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks