General

  • Target

    9cb68977e78b44a60c9f4a2ea0982ccdb43310b0ecc19e2bd081c11f912c9db4

  • Size

    235KB

  • Sample

    240629-plyvcazhkk

  • MD5

    98963219310e47408fc9bea87f159738

  • SHA1

    8be2566e4d6e631500bb3e6c0ea4bd6c039c6c5c

  • SHA256

    9cb68977e78b44a60c9f4a2ea0982ccdb43310b0ecc19e2bd081c11f912c9db4

  • SHA512

    c08f4c2e6d3b6c7fb31093e5fc377306a89472e1a38a688efa2cd0ac4ad914c55ff22c237412a908dbb9dc1e6c46862071ed801fc0b4a0360d236f53f9658dc1

  • SSDEEP

    3072:2Dkkrl4W2tYB5Wn4OfLDFdoIhWp+USIxz9C1fsapl1D+r+68:Irl4WCYanDFd0p3t9ChsafEr+

Score
10/10

Malware Config

Extracted

Family

gcleaner

C2

185.172.128.90

185.172.128.69

Attributes
  • url_path

    /advdlc.php

Targets

    • Target

      9cb68977e78b44a60c9f4a2ea0982ccdb43310b0ecc19e2bd081c11f912c9db4

    • Size

      235KB

    • MD5

      98963219310e47408fc9bea87f159738

    • SHA1

      8be2566e4d6e631500bb3e6c0ea4bd6c039c6c5c

    • SHA256

      9cb68977e78b44a60c9f4a2ea0982ccdb43310b0ecc19e2bd081c11f912c9db4

    • SHA512

      c08f4c2e6d3b6c7fb31093e5fc377306a89472e1a38a688efa2cd0ac4ad914c55ff22c237412a908dbb9dc1e6c46862071ed801fc0b4a0360d236f53f9658dc1

    • SSDEEP

      3072:2Dkkrl4W2tYB5Wn4OfLDFdoIhWp+USIxz9C1fsapl1D+r+68:Irl4WCYanDFd0p3t9ChsafEr+

    Score
    10/10
    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Deletes itself

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks