General

  • Target

    bcf9d9afcd4a13f49a3df860666e076cd87f88a47b2c97bd8d60c3719335ced6

  • Size

    5.8MB

  • Sample

    240630-g5bvxsvakb

  • MD5

    93abf6b6c90f0d5a5b5211fb67dadc74

  • SHA1

    79c7e8f806f51e149634a238a3e4e28067bb7bd0

  • SHA256

    bcf9d9afcd4a13f49a3df860666e076cd87f88a47b2c97bd8d60c3719335ced6

  • SHA512

    a06698d20011c19d10ad0db0e6486cd5ea2e5d653051275193d2f3008d21e9e52f4688edcd07501e84f77189cf941f066032f22f6a54afe85516ca2098242f23

  • SSDEEP

    98304:Cze2df9cx1hD/JNmlovT2clFC6sJPrWvOgLwCB6c3kESDP5Ue/aSCtSQTWY:qreDh0ovT2clFCtlSPkEFhL

Malware Config

Targets

    • Target

      bcf9d9afcd4a13f49a3df860666e076cd87f88a47b2c97bd8d60c3719335ced6

    • Size

      5.8MB

    • MD5

      93abf6b6c90f0d5a5b5211fb67dadc74

    • SHA1

      79c7e8f806f51e149634a238a3e4e28067bb7bd0

    • SHA256

      bcf9d9afcd4a13f49a3df860666e076cd87f88a47b2c97bd8d60c3719335ced6

    • SHA512

      a06698d20011c19d10ad0db0e6486cd5ea2e5d653051275193d2f3008d21e9e52f4688edcd07501e84f77189cf941f066032f22f6a54afe85516ca2098242f23

    • SSDEEP

      98304:Cze2df9cx1hD/JNmlovT2clFC6sJPrWvOgLwCB6c3kESDP5Ue/aSCtSQTWY:qreDh0ovT2clFCtlSPkEFhL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Tasks