General

  • Target

    6b27b5b13f59cea17f9b9685b5119640.bin

  • Size

    43.5MB

  • Sample

    240630-cweg8ssdra

  • MD5

    6b27b5b13f59cea17f9b9685b5119640

  • SHA1

    30bed25161c53bdd3bb901dea2896c93471500f1

  • SHA256

    055b0426a2519c9e388863d176929b21183f75d470d6d34134461a10bca13ab5

  • SHA512

    c685fa45607f888d073874d89ecb0773a67653f4cc7e3cb9cf0db56d3ce0ebc524565572facd453ce9074f0561e4be897b2a9a763e21f89bd835264b8d44d5a9

  • SSDEEP

    786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVX80:xwvn7yBVea3zFCK/8J75RvzZ6EEgVn

Malware Config

Targets

    • Target

      6b27b5b13f59cea17f9b9685b5119640.bin

    • Size

      43.5MB

    • MD5

      6b27b5b13f59cea17f9b9685b5119640

    • SHA1

      30bed25161c53bdd3bb901dea2896c93471500f1

    • SHA256

      055b0426a2519c9e388863d176929b21183f75d470d6d34134461a10bca13ab5

    • SHA512

      c685fa45607f888d073874d89ecb0773a67653f4cc7e3cb9cf0db56d3ce0ebc524565572facd453ce9074f0561e4be897b2a9a763e21f89bd835264b8d44d5a9

    • SSDEEP

      786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVX80:xwvn7yBVea3zFCK/8J75RvzZ6EEgVn

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks