General

  • Target

    c98b100bb7cab5efc69bb852f8612032.bin

  • Size

    222KB

  • Sample

    240628-dmt21a1bjr

  • MD5

    c98b100bb7cab5efc69bb852f8612032

  • SHA1

    ee6e00cb8dbef0a1b3636c891dc9925cee3ff29c

  • SHA256

    e316d772223d0fe829c62fea1eda35990362d8f7cc02968fd0bb8c7d2fde2959

  • SHA512

    8b7c3dac818ee6ffcdcc0cc9d44c18bc53f5dc443535334f139502b15ed516108e70ef744f1c93a865099de4d3d9d9ab96af7ee361b6f03ae15e88d7790ea8e7

  • SSDEEP

    3072:9BbWxYKFDnqvffIj0nStxBN3cwqvcQr3YTfVEPnYbl3/YrDAEioKhAv/:9BkYKZSYYnS1xecmoT2nYbdEKs/

Malware Config

Targets

    • Target

      c98b100bb7cab5efc69bb852f8612032.bin

    • Size

      222KB

    • MD5

      c98b100bb7cab5efc69bb852f8612032

    • SHA1

      ee6e00cb8dbef0a1b3636c891dc9925cee3ff29c

    • SHA256

      e316d772223d0fe829c62fea1eda35990362d8f7cc02968fd0bb8c7d2fde2959

    • SHA512

      8b7c3dac818ee6ffcdcc0cc9d44c18bc53f5dc443535334f139502b15ed516108e70ef744f1c93a865099de4d3d9d9ab96af7ee361b6f03ae15e88d7790ea8e7

    • SSDEEP

      3072:9BbWxYKFDnqvffIj0nStxBN3cwqvcQr3YTfVEPnYbl3/YrDAEioKhAv/:9BkYKZSYYnS1xecmoT2nYbdEKs/

    • GandCrab payload

    • Gandcrab

      Gandcrab is a Trojan horse that encrypts files on a computer.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks