General

  • Target

    ac143bbf394e1dd9a281980e589acc6c.bin

  • Size

    43.5MB

  • Sample

    240630-dvnj7awgpk

  • MD5

    ac143bbf394e1dd9a281980e589acc6c

  • SHA1

    e9e1e0f5e85944ff41e025a441fd74c02da65886

  • SHA256

    cbbfa2233e7bd402b84889a68c8645c3e45e3856145a502ce996acf0ca7cfc0b

  • SHA512

    14ac960a48224718c2912030d76779cf5a0b0bde775b57e1910a3c25dcba057be6433953549a6c1e35b18ea42ecc4ca373762e4f8d3259acd4bba8d31a55cec9

  • SSDEEP

    786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXz:xwvn7yBVea3zFCK/8J75RvzZ6EEgVj

Malware Config

Targets

    • Target

      ac143bbf394e1dd9a281980e589acc6c.bin

    • Size

      43.5MB

    • MD5

      ac143bbf394e1dd9a281980e589acc6c

    • SHA1

      e9e1e0f5e85944ff41e025a441fd74c02da65886

    • SHA256

      cbbfa2233e7bd402b84889a68c8645c3e45e3856145a502ce996acf0ca7cfc0b

    • SHA512

      14ac960a48224718c2912030d76779cf5a0b0bde775b57e1910a3c25dcba057be6433953549a6c1e35b18ea42ecc4ca373762e4f8d3259acd4bba8d31a55cec9

    • SSDEEP

      786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXz:xwvn7yBVea3zFCK/8J75RvzZ6EEgVj

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks