General
-
Target
Orbit_Loader.exe
-
Size
5.5MB
-
Sample
240630-f7cpkatgrh
-
MD5
7850ea6b5955e49885d636124ceffdf3
-
SHA1
3ce1d1e0153bc125c41c12facc7eb66cb418cea7
-
SHA256
959fc2e0b561354c21c0d7136a05cc454becc4f3a33d81ad7e6f4a66440da703
-
SHA512
a8f800516d324f02d9f75e8d20ea178827bab9115e601683259ab351aaf4e2e0851054ca52adef1101903934d3c993be915634b19cfbfe9122c686ebb160acd8
-
SSDEEP
98304:qU34GV+6SRJMvKO95dDoBWuMGhzLxPhn4+lcRP6+PeXA75vh8AEMjFEpg6/6fhsg:qUoGY6SR8jTdkBEGd1PhncfPeQNvM110
Behavioral task
behavioral1
Sample
Orbit_Loader.exe
Resource
win7-20240611-en
Malware Config
Targets
-
-
Target
Orbit_Loader.exe
-
Size
5.5MB
-
MD5
7850ea6b5955e49885d636124ceffdf3
-
SHA1
3ce1d1e0153bc125c41c12facc7eb66cb418cea7
-
SHA256
959fc2e0b561354c21c0d7136a05cc454becc4f3a33d81ad7e6f4a66440da703
-
SHA512
a8f800516d324f02d9f75e8d20ea178827bab9115e601683259ab351aaf4e2e0851054ca52adef1101903934d3c993be915634b19cfbfe9122c686ebb160acd8
-
SSDEEP
98304:qU34GV+6SRJMvKO95dDoBWuMGhzLxPhn4+lcRP6+PeXA75vh8AEMjFEpg6/6fhsg:qUoGY6SR8jTdkBEGd1PhncfPeQNvM110
-
Identifies VirtualBox via ACPI registry values (likely anti-VM)
-
Checks BIOS information in registry
BIOS information is often read in order to detect sandboxing environments.
-
Suspicious use of NtSetInformationThreadHideFromDebugger
-