General

  • Target

    External24.exe

  • Size

    2.4MB

  • Sample

    240628-v9edhaxfkf

  • MD5

    e8af10713a9e8ee414a1a0865c2379f2

  • SHA1

    12193121a75325ca4a32e7260d82e6d8c85fe0d4

  • SHA256

    acad873da34aab461e8a7b87dd2c6d98c3b2b187f5ca868415bac26af1516da5

  • SHA512

    3fb65941ec7a0a979ad055dc62f240b8de4e6e2d7b5566e97eec43d695bf77653e6ea4882abeae55e9558d2e0b734985e58b712823b4ba20fb10ad8377fa833a

  • SSDEEP

    49152:PMa2yfLmOYmaAkjwyI36HznuE1djDUGNywFVf8o0pBsBZOJ:PFctk36jxDU+LVEoQsOJ

Score
10/10

Malware Config

Targets

    • Target

      External24.exe

    • Size

      2.4MB

    • MD5

      e8af10713a9e8ee414a1a0865c2379f2

    • SHA1

      12193121a75325ca4a32e7260d82e6d8c85fe0d4

    • SHA256

      acad873da34aab461e8a7b87dd2c6d98c3b2b187f5ca868415bac26af1516da5

    • SHA512

      3fb65941ec7a0a979ad055dc62f240b8de4e6e2d7b5566e97eec43d695bf77653e6ea4882abeae55e9558d2e0b734985e58b712823b4ba20fb10ad8377fa833a

    • SSDEEP

      49152:PMa2yfLmOYmaAkjwyI36HznuE1djDUGNywFVf8o0pBsBZOJ:PFctk36jxDU+LVEoQsOJ

    Score
    10/10
    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Process Discovery

1
T1057

Tasks