General

  • Target

    BananaBot.exe

  • Size

    2.7MB

  • Sample

    240629-lgzdjavcqe

  • MD5

    8063181c476db09b6cc2df0d31e36559

  • SHA1

    26e1303e7599d11977ecbde0885a63f6b32b7086

  • SHA256

    d420da458ca2f642d7f541219cc71ddea42f236c7889c04de4733f08d9b89170

  • SHA512

    b56da66f2f9c7f992e5fc4572645fd8e5287a6b54e9affe9d6484bfd2a7c936450a60b705edf566fe57a4b2e175be1f36b284500c6c39ef93695cf73bef5e533

  • SSDEEP

    49152:vDjlabwz9XDjlabwz9ngfAM7tzqosdnzrL+QppFj97enzGsz4QX:bqwBqwhAAo4zWKZ7ef4Q

Malware Config

Targets

    • Target

      BananaBot.exe

    • Size

      2.7MB

    • MD5

      8063181c476db09b6cc2df0d31e36559

    • SHA1

      26e1303e7599d11977ecbde0885a63f6b32b7086

    • SHA256

      d420da458ca2f642d7f541219cc71ddea42f236c7889c04de4733f08d9b89170

    • SHA512

      b56da66f2f9c7f992e5fc4572645fd8e5287a6b54e9affe9d6484bfd2a7c936450a60b705edf566fe57a4b2e175be1f36b284500c6c39ef93695cf73bef5e533

    • SSDEEP

      49152:vDjlabwz9XDjlabwz9ngfAM7tzqosdnzrL+QppFj97enzGsz4QX:bqwBqwhAAo4zWKZ7ef4Q

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Remote System Discovery

1
T1018

Collection

Data from Local System

1
T1005

Tasks