General

  • Target

    SecuriteInfo.com.Win64.Evo-gen.23205.20359.exe

  • Size

    12.6MB

  • Sample

    240629-ty8brsthlj

  • MD5

    0fd93d95f5427314c472acf35a741bd8

  • SHA1

    82c4a03fc289ff7231a55c781838a07cf2cb3afd

  • SHA256

    cb8109d659672303e80f6666d566f8192f3134d3d67048e1a60ff3ace62c66f5

  • SHA512

    566a7036ccc924aee8b49b69c031b5e77ca85f4ff643db5c82e0ac9533a1a687c844858ae0de080dc29ecc6d74b95cc0eca50d7ccc8f158104e32d2dd241f518

  • SSDEEP

    196608:yL9vGiCff7yl3nCIjvDMjYeVa65nT84FMIZETSwjPePdrQJ/BGOqJ9Au5DYPF:yLdGiCbsSIrDMjPgQETSwvJEOqQYDQ

Malware Config

Targets

    • Target

      SecuriteInfo.com.Win64.Evo-gen.23205.20359.exe

    • Size

      12.6MB

    • MD5

      0fd93d95f5427314c472acf35a741bd8

    • SHA1

      82c4a03fc289ff7231a55c781838a07cf2cb3afd

    • SHA256

      cb8109d659672303e80f6666d566f8192f3134d3d67048e1a60ff3ace62c66f5

    • SHA512

      566a7036ccc924aee8b49b69c031b5e77ca85f4ff643db5c82e0ac9533a1a687c844858ae0de080dc29ecc6d74b95cc0eca50d7ccc8f158104e32d2dd241f518

    • SSDEEP

      196608:yL9vGiCff7yl3nCIjvDMjYeVa65nT84FMIZETSwjPePdrQJ/BGOqJ9Au5DYPF:yLdGiCbsSIrDMjPgQETSwvJEOqQYDQ

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Loads dropped DLL

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks