General

  • Target

    avast_free_antivirus_setup_online.exe

  • Size

    257KB

  • Sample

    240630-h91waayank

  • MD5

    aa966bc6a746f2b7725b4cd5f90a42c5

  • SHA1

    111fbd75da6137695e6935a41ca6ee4395fd8a3b

  • SHA256

    1d3dd60c0bbd7c214146171304c811bb82eb044f97fdac6dc11af485221069d6

  • SHA512

    8001d8ece5a0e5442a7826d6dd3dbc891ddd96015826b9b3bfb35a54a864153570c3775fa0f1d14a1799adc401eb1442a83bd3e6b5a7bf423714f425b953c383

  • SSDEEP

    3072:42RaiKg4xmUh1WXHqw/l+qmOELhakVsm3mxB32tLEv8zfdn5f2dZLCozOhh3n+Tt:40KgGwHqwOOELha+sm2D2+UhnguEC

Score
6/10

Malware Config

Targets

    • Target

      avast_free_antivirus_setup_online.exe

    • Size

      257KB

    • MD5

      aa966bc6a746f2b7725b4cd5f90a42c5

    • SHA1

      111fbd75da6137695e6935a41ca6ee4395fd8a3b

    • SHA256

      1d3dd60c0bbd7c214146171304c811bb82eb044f97fdac6dc11af485221069d6

    • SHA512

      8001d8ece5a0e5442a7826d6dd3dbc891ddd96015826b9b3bfb35a54a864153570c3775fa0f1d14a1799adc401eb1442a83bd3e6b5a7bf423714f425b953c383

    • SSDEEP

      3072:42RaiKg4xmUh1WXHqw/l+qmOELhakVsm3mxB32tLEv8zfdn5f2dZLCozOhh3n+Tt:40KgGwHqwOOELha+sm2D2+UhnguEC

    Score
    6/10
    • Checks for any installed AV software in registry

    • Downloads MZ/PE file

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Software Discovery

1
T1518

Security Software Discovery

1
T1518.001

Query Registry

1
T1012

System Information Discovery

1
T1082

Tasks