General

  • Target

    8502ecb06d392ee6d5c40569a2c5e044.bin

  • Size

    43.5MB

  • Sample

    240630-c8xvcasfng

  • MD5

    8502ecb06d392ee6d5c40569a2c5e044

  • SHA1

    0bd5c7cf7854e371e52a8c26ab36bf20398d4021

  • SHA256

    316140a68d91f0101ca34e7347b49294f9cb8fa36aeabf3e4063f6b7e006b58d

  • SHA512

    5a8f4bec21eed5e31e1298fca590d1b3122f96ace90f11a6a00cdfbb8561d045bb1d8f5d5be546c28ae6ad7efd278994fb8583597419879b819bc51c1c7771b3

  • SSDEEP

    786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXi:xwvn7yBVea3zFCK/8J75RvzZ6EEgVy

Malware Config

Targets

    • Target

      8502ecb06d392ee6d5c40569a2c5e044.bin

    • Size

      43.5MB

    • MD5

      8502ecb06d392ee6d5c40569a2c5e044

    • SHA1

      0bd5c7cf7854e371e52a8c26ab36bf20398d4021

    • SHA256

      316140a68d91f0101ca34e7347b49294f9cb8fa36aeabf3e4063f6b7e006b58d

    • SHA512

      5a8f4bec21eed5e31e1298fca590d1b3122f96ace90f11a6a00cdfbb8561d045bb1d8f5d5be546c28ae6ad7efd278994fb8583597419879b819bc51c1c7771b3

    • SSDEEP

      786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXi:xwvn7yBVea3zFCK/8J75RvzZ6EEgVy

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks