General

  • Target

    WaveInstaller.rar

  • Size

    82KB

  • Sample

    240628-v4yvysxemd

  • MD5

    f2768da94a45433f5b9cd380d1ee9701

  • SHA1

    4f9f8ab92e49895253c4cdadcb2895271a3515fb

  • SHA256

    e669f3bc914d22c2e24dd7f7af3a0008cc7b836dbee529c69760b56cd38032e7

  • SHA512

    1d13e10f1b4862f97443aeb92a4d716d09894b481b5bbdd2de661428877ee4a5f48a3d1615c27b06d8c2529754c883ee7fc20ba150d2e8ce1a3a0a3685b23f09

  • SSDEEP

    1536:Cg5Du81UykuZZfNMjO6lWbbTsUAXuHvMPQtTN97XE5kCE8VZzz6N/:TDunOgjPYz97XqrPVZz8

Score
10/10

Malware Config

Targets

    • Target

      WaveInstaller.rar

    • Size

      82KB

    • MD5

      f2768da94a45433f5b9cd380d1ee9701

    • SHA1

      4f9f8ab92e49895253c4cdadcb2895271a3515fb

    • SHA256

      e669f3bc914d22c2e24dd7f7af3a0008cc7b836dbee529c69760b56cd38032e7

    • SHA512

      1d13e10f1b4862f97443aeb92a4d716d09894b481b5bbdd2de661428877ee4a5f48a3d1615c27b06d8c2529754c883ee7fc20ba150d2e8ce1a3a0a3685b23f09

    • SSDEEP

      1536:Cg5Du81UykuZZfNMjO6lWbbTsUAXuHvMPQtTN97XE5kCE8VZzz6N/:TDunOgjPYz97XqrPVZz8

    Score
    10/10
    • Detect Umbral payload

    • Umbral

      Umbral stealer is an opensource moduler stealer written in C#.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks