General

  • Target

    ae29b4ecc86770671a65c6922c829421.bin

  • Size

    43.5MB

  • Sample

    240630-dznqratbmh

  • MD5

    ae29b4ecc86770671a65c6922c829421

  • SHA1

    77f425eeb5a1ab26d05a795dcc81731d0c7d7ea1

  • SHA256

    8155c20dfd5bd11a8a7e6fbb993c8eb7541ff7164a4f1e0468577a572962910c

  • SHA512

    015ff3de6bb59d74e415038e27512c3144a17b3baa19939301a934a8232102ae336dac406df6c65386082a126195d6f74cfcc554aee2fb35851ea4c4f2caf495

  • SSDEEP

    786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXH:xwvn7yBVea3zFCK/8J75RvzZ6EEgV3

Malware Config

Targets

    • Target

      ae29b4ecc86770671a65c6922c829421.bin

    • Size

      43.5MB

    • MD5

      ae29b4ecc86770671a65c6922c829421

    • SHA1

      77f425eeb5a1ab26d05a795dcc81731d0c7d7ea1

    • SHA256

      8155c20dfd5bd11a8a7e6fbb993c8eb7541ff7164a4f1e0468577a572962910c

    • SHA512

      015ff3de6bb59d74e415038e27512c3144a17b3baa19939301a934a8232102ae336dac406df6c65386082a126195d6f74cfcc554aee2fb35851ea4c4f2caf495

    • SSDEEP

      786432:xwvnIe84yEZwcCUmeaeYzeyChA/tQ1/BJ754U/Hz4gQ7sCZzEECamVXH:xwvn7yBVea3zFCK/8J75RvzZ6EEgV3

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks