General

  • Target

    PROPER EDUCATION.docx

  • Size

    11KB

  • Sample

    240629-l44a1aybln

  • MD5

    6409cdd4687dc59b5e0fa3a8d94f625f

  • SHA1

    77a3a65326dfe834cd026743fe3119131db6eabe

  • SHA256

    0c720da75f3cdc5cbd84450075783822fb9e40e0558ade24398bfb92de372fda

  • SHA512

    bcb3324bb654ff40c527baa07246a1f8b3df70b59a6ba3af0f3fd16c1d57801fbfb58256136d04903a8062f61f7224fbf4dd7c5ca6b5b8f32d03cc7c6b85e608

  • SSDEEP

    192:CtiVC0zCCNxtpgoZ22NNxD/oKvFfghsKwVONL0WMGTlflHmACM0j7:aiA0zdNxt/ZtNNl3y7WGTldHmJM0j7

Score
6/10

Malware Config

Targets

    • Target

      PROPER EDUCATION.docx

    • Size

      11KB

    • MD5

      6409cdd4687dc59b5e0fa3a8d94f625f

    • SHA1

      77a3a65326dfe834cd026743fe3119131db6eabe

    • SHA256

      0c720da75f3cdc5cbd84450075783822fb9e40e0558ade24398bfb92de372fda

    • SHA512

      bcb3324bb654ff40c527baa07246a1f8b3df70b59a6ba3af0f3fd16c1d57801fbfb58256136d04903a8062f61f7224fbf4dd7c5ca6b5b8f32d03cc7c6b85e608

    • SSDEEP

      192:CtiVC0zCCNxtpgoZ22NNxD/oKvFfghsKwVONL0WMGTlflHmACM0j7:aiA0zdNxt/ZtNNl3y7WGTldHmJM0j7

    Score
    6/10
    • Process spawned suspicious child process

      This child process is typically not spawned unless (for example) the parent process crashes. This typically indicates the parent process was unsuccessfully compromised.

    • Detected potential entity reuse from brand microsoft.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

3
T1082

Tasks