General
-
Target
Freshbuild.exe
-
Size
415KB
-
Sample
240629-n985jsxckh
-
MD5
07101cac5b9477ba636cd8ca7b9932cb
-
SHA1
59ea7fd9ae6ded8c1b7240a4bf9399b4eb3849f1
-
SHA256
488385cd54d14790b03fa7c7dc997ebea3f7b2a8499e5927eb437a3791102a77
-
SHA512
02240ff51a74966bc31cfcc901105096eb871f588efaa9be1a829b4ee6f245bd9dca37be7e2946ba6315feea75c3dce5f490847250e62081445cd25b0f406887
-
SSDEEP
12288:5fSPtGpmLb84Jjzo6yrBuKuJ+ITOC0Ud:UtGpmf8edykhV0Ud
Behavioral task
behavioral1
Sample
Freshbuild.exe
Resource
win10-20240404-en
Behavioral task
behavioral2
Sample
Freshbuild.exe
Resource
win7-20240508-en
Behavioral task
behavioral3
Sample
Freshbuild.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral4
Sample
Freshbuild.exe
Resource
win11-20240611-en
Malware Config
Extracted
amadey
4.30
4b955f
http://185.172.128.116
-
install_dir
b66a8ae076
-
install_file
Hkbsse.exe
-
strings_key
d0f1609e2fff913c5fc0b879a0d56e06
-
url_paths
/Mb3GvQs8/index.php
Targets
-
-
Target
Freshbuild.exe
-
Size
415KB
-
MD5
07101cac5b9477ba636cd8ca7b9932cb
-
SHA1
59ea7fd9ae6ded8c1b7240a4bf9399b4eb3849f1
-
SHA256
488385cd54d14790b03fa7c7dc997ebea3f7b2a8499e5927eb437a3791102a77
-
SHA512
02240ff51a74966bc31cfcc901105096eb871f588efaa9be1a829b4ee6f245bd9dca37be7e2946ba6315feea75c3dce5f490847250e62081445cd25b0f406887
-
SSDEEP
12288:5fSPtGpmLb84Jjzo6yrBuKuJ+ITOC0Ud:UtGpmf8edykhV0Ud
Score8/10-
Downloads MZ/PE file
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Executes dropped EXE
-
Loads dropped DLL
-