General

  • Target

    LUNA RAIDER.exe

  • Size

    8.2MB

  • Sample

    240629-da4exasepk

  • MD5

    0437fa16eec1dedfd1ddf69afcccbf0f

  • SHA1

    1649d8123ebbbc26857b0383efbbc8c329f23161

  • SHA256

    01b82e741a88ef644df41689744f4a883d25f4ea3ad172b0a7c61b9d7eddd712

  • SHA512

    5e995a9b3ec1cee80700f4c7f264b09f826a67bdfc65c67bb848815f5289656580e3f62853e0397da0a425ba28fabe385674320d53c36363abab2b2497de5eb2

  • SSDEEP

    196608:b2qInJf+oTjOGNW+8u8tMmo/UIaIZQHFUQsGZgqBPtgsV:b2qIn4GN8osIVZQu6gAFgk

Malware Config

Targets

    • Target

      LUNA RAIDER.exe

    • Size

      8.2MB

    • MD5

      0437fa16eec1dedfd1ddf69afcccbf0f

    • SHA1

      1649d8123ebbbc26857b0383efbbc8c329f23161

    • SHA256

      01b82e741a88ef644df41689744f4a883d25f4ea3ad172b0a7c61b9d7eddd712

    • SHA512

      5e995a9b3ec1cee80700f4c7f264b09f826a67bdfc65c67bb848815f5289656580e3f62853e0397da0a425ba28fabe385674320d53c36363abab2b2497de5eb2

    • SSDEEP

      196608:b2qInJf+oTjOGNW+8u8tMmo/UIaIZQHFUQsGZgqBPtgsV:b2qIn4GN8osIVZQu6gAFgk

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • AgentTesla payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Obfuscated with Agile.Net obfuscator

      Detects use of the Agile.Net commercial obfuscator, which is capable of entity renaming and control flow obfuscation.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

3
T1012

System Information Discovery

3
T1082

Tasks