General

  • Target

    vn-woofer.exe

  • Size

    3.9MB

  • Sample

    240629-ydz7wathrb

  • MD5

    0e9feb3b1dd3a58fb2ffbf84ff2fb40a

  • SHA1

    4bfc7870ac362f1f490aa5dd6e857aff95a435b9

  • SHA256

    37bd834e86edab2afe1b3d12b28ce28a268e8c761d88dc8528651813cb2b7f1c

  • SHA512

    9403537f3f60d7062d74db56ed6bff8f87805a946c3416b483539b8fb28d2364ebdcc37d9b018979a708f3cc798948e9395677513a1e4e6c72926bc3c91d6cd8

  • SSDEEP

    98304:t5zIgQfwnF+pbZlkLkxMc7Hk71xdnkomKe:t5zIfIn8pbPz2xxkoy

Malware Config

Targets

    • Target

      vn-woofer.exe

    • Size

      3.9MB

    • MD5

      0e9feb3b1dd3a58fb2ffbf84ff2fb40a

    • SHA1

      4bfc7870ac362f1f490aa5dd6e857aff95a435b9

    • SHA256

      37bd834e86edab2afe1b3d12b28ce28a268e8c761d88dc8528651813cb2b7f1c

    • SHA512

      9403537f3f60d7062d74db56ed6bff8f87805a946c3416b483539b8fb28d2364ebdcc37d9b018979a708f3cc798948e9395677513a1e4e6c72926bc3c91d6cd8

    • SSDEEP

      98304:t5zIgQfwnF+pbZlkLkxMc7Hk71xdnkomKe:t5zIfIn8pbPz2xxkoy

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

3
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

4
T1082

Tasks