General

  • Target

    Nado_MultiTool.exe

  • Size

    6.5MB

  • Sample

    240627-xxv7laybmm

  • MD5

    e442352d6870d0a0a54a52df6072dd0c

  • SHA1

    7ff5400d6ae2e46988bc34b0023918e7dafaf509

  • SHA256

    ceb89c17dee95e5cd84f9d2d17829ee99bbe64c19316e23a2c712b437dbe3966

  • SHA512

    53c81585ee16bdc2936afe71910d001fe40f927e032a0abee8412c5cebf3a62808d9806820cd9f7d7777f341b7b464173c352b334c1e9d7d2493410f1c799605

  • SSDEEP

    196608:grCASUHWP3ny4a488g8i51eO3nBVJ/lhZICFNaHJ6VMGW:9ASUd4y8i5LnBVZlXIEkp6V

Score
10/10

Malware Config

Targets

    • Target

      Nado_MultiTool.exe

    • Size

      6.5MB

    • MD5

      e442352d6870d0a0a54a52df6072dd0c

    • SHA1

      7ff5400d6ae2e46988bc34b0023918e7dafaf509

    • SHA256

      ceb89c17dee95e5cd84f9d2d17829ee99bbe64c19316e23a2c712b437dbe3966

    • SHA512

      53c81585ee16bdc2936afe71910d001fe40f927e032a0abee8412c5cebf3a62808d9806820cd9f7d7777f341b7b464173c352b334c1e9d7d2493410f1c799605

    • SSDEEP

      196608:grCASUHWP3ny4a488g8i51eO3nBVJ/lhZICFNaHJ6VMGW:9ASUd4y8i5LnBVZlXIEkp6V

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Legitimate hosting services abused for malware hosting/C2

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Command and Control

Web Service

1
T1102

Tasks