General

  • Target

    Nado_MultiTool.exe

  • Size

    6.6MB

  • Sample

    240627-zevjfszbng

  • MD5

    ee82b3877e3646e4f44c8cc2157c790a

  • SHA1

    5a55ab64d5248e82d2d6919e41aad486628f34b8

  • SHA256

    33902244bb1b5176b53676d3536561d6cdc9f5f99e9bb05ff2bb5caf7b74b05e

  • SHA512

    cd45633fc776c3952c51f37b2ff139fcfaaaaf547d7906b68d0a39261c84416567d0004d93ee0a4111234f42bb84651418cf763cd78af10b32e81918427abcca

  • SSDEEP

    196608:PlmWr+jGNqKoKC3ujfGny5vkbmjTh9DEu6iovb:tJ2GPoLeey5vSqhtEjiov

Score
10/10

Malware Config

Targets

    • Target

      Nado_MultiTool.exe

    • Size

      6.6MB

    • MD5

      ee82b3877e3646e4f44c8cc2157c790a

    • SHA1

      5a55ab64d5248e82d2d6919e41aad486628f34b8

    • SHA256

      33902244bb1b5176b53676d3536561d6cdc9f5f99e9bb05ff2bb5caf7b74b05e

    • SHA512

      cd45633fc776c3952c51f37b2ff139fcfaaaaf547d7906b68d0a39261c84416567d0004d93ee0a4111234f42bb84651418cf763cd78af10b32e81918427abcca

    • SSDEEP

      196608:PlmWr+jGNqKoKC3ujfGny5vkbmjTh9DEu6iovb:tJ2GPoLeey5vSqhtEjiov

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Legitimate hosting services abused for malware hosting/C2

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Tasks