Resubmissions

29-06-2024 12:43

240629-px6z4a1app 7

22-05-2024 07:25

240522-h9f6wagc6y 10

General

  • Target

    pojgysef.exe

  • Size

    6.1MB

  • Sample

    240629-px6z4a1app

  • MD5

    d4f738f4e3787ef0b31891e446919aa8

  • SHA1

    fa22c2fe4da02adbb51c35402c8dc21ab4157c43

  • SHA256

    11fe45cccad95a86b7e7d29c9d92547dae0706d549485d37d482d3df5fe58ebb

  • SHA512

    19d3a88cc2367669d6df8d5e7f4f310e482699c365a72cc7d2ee384972e6a2441a4adfc2c348780658c2e88a3e6f8ad82ecae1b4637d8f7cabb447266e16d3c7

  • SSDEEP

    196608:a7m6/UXOd2L2Y4QE2i7fQzrVmbLm5g53D9I:eAOIL2Yfi7fymHmK5z9I

Score
7/10

Malware Config

Targets

    • Target

      pojgysef.exe

    • Size

      6.1MB

    • MD5

      d4f738f4e3787ef0b31891e446919aa8

    • SHA1

      fa22c2fe4da02adbb51c35402c8dc21ab4157c43

    • SHA256

      11fe45cccad95a86b7e7d29c9d92547dae0706d549485d37d482d3df5fe58ebb

    • SHA512

      19d3a88cc2367669d6df8d5e7f4f310e482699c365a72cc7d2ee384972e6a2441a4adfc2c348780658c2e88a3e6f8ad82ecae1b4637d8f7cabb447266e16d3c7

    • SSDEEP

      196608:a7m6/UXOd2L2Y4QE2i7fQzrVmbLm5g53D9I:eAOIL2Yfi7fymHmK5z9I

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks