General

  • Target

    pa collective agreement pay 65328.js

  • Size

    27.8MB

  • Sample

    240628-qmvpravbnn

  • MD5

    2a6f1d027b45097b6a909d40151327c9

  • SHA1

    9eec6fd29b10da65c87643b7e1d1ce7c4cb50a96

  • SHA256

    1c2ba1ce390b721a5b27b18e39f3ea6c14f3b6656a4a9e9fc29c8716b9f3467b

  • SHA512

    5abf113d764629ff2285ae3651fe804040e7a00bdd034f8b87ec3bd578a6a93591d041bbe8bdb9f6b55e6854281cae640ef11ad49abaa50d36eb756a9df8bfcb

  • SSDEEP

    98304:31c43mp1c43mp1c43mp1c43mp1c43mp1c43ml:L

Malware Config

Targets

    • Target

      pa collective agreement pay 65328.js

    • Size

      27.8MB

    • MD5

      2a6f1d027b45097b6a909d40151327c9

    • SHA1

      9eec6fd29b10da65c87643b7e1d1ce7c4cb50a96

    • SHA256

      1c2ba1ce390b721a5b27b18e39f3ea6c14f3b6656a4a9e9fc29c8716b9f3467b

    • SHA512

      5abf113d764629ff2285ae3651fe804040e7a00bdd034f8b87ec3bd578a6a93591d041bbe8bdb9f6b55e6854281cae640ef11ad49abaa50d36eb756a9df8bfcb

    • SSDEEP

      98304:31c43mp1c43mp1c43mp1c43mp1c43mp1c43ml:L

    • GootLoader

      JavaScript loader known for delivering other families such as Gootkit and Cobaltstrike.

    • Blocklisted process makes network request

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

JavaScript

1
T1059.007

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks