General

  • Target

    Beatware.Internal.v1.7.exe

  • Size

    8.3MB

  • Sample

    240628-s29hkawakb

  • MD5

    1fbd8db9291a9ee4622ee2accc493ba0

  • SHA1

    66cdda6c2789202f6c5f92a4e9bb970f3e095a9d

  • SHA256

    9fffea08116948a80151baf5271b5ba94d54e11d4c9aa7315591626d11ac0242

  • SHA512

    744f62ebc60cbe7c9f23c64e5e98c5309b673a8ff2b6c743bc4c27655efcdb43ea68474d6f39160adf74baf65c5036f8ea17b73038fb6ddd04698b5b1cdcccc5

  • SSDEEP

    98304:mn2ihaZdUjS6fzR1vQ6cbrgsihQ4xbNs8kwzXRuLHJD1UQ17VOhKMVtOwwMltcc:O2i0IV7RtQhihDbNs8VRORSQsKM3Hwf

Score
7/10

Malware Config

Targets

    • Target

      Beatware.Internal.v1.7.exe

    • Size

      8.3MB

    • MD5

      1fbd8db9291a9ee4622ee2accc493ba0

    • SHA1

      66cdda6c2789202f6c5f92a4e9bb970f3e095a9d

    • SHA256

      9fffea08116948a80151baf5271b5ba94d54e11d4c9aa7315591626d11ac0242

    • SHA512

      744f62ebc60cbe7c9f23c64e5e98c5309b673a8ff2b6c743bc4c27655efcdb43ea68474d6f39160adf74baf65c5036f8ea17b73038fb6ddd04698b5b1cdcccc5

    • SSDEEP

      98304:mn2ihaZdUjS6fzR1vQ6cbrgsihQ4xbNs8kwzXRuLHJD1UQ17VOhKMVtOwwMltcc:O2i0IV7RtQhihDbNs8VRORSQsKM3Hwf

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Legitimate hosting services abused for malware hosting/C2

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

System Information Discovery

2
T1082

Query Registry

1
T1012

Command and Control

Web Service

1
T1102

Tasks