General

  • Target

    dllmain.exe

  • Size

    229KB

  • MD5

    411156b1cc6ca8a2722edb9a9bf15991

  • SHA1

    93441490e31783317bb8b3c2e4a9d0916eb4674d

  • SHA256

    0697ab58f1b4c94620982f20ffc2e1069974a7f4c38c804e3a15a3d3f54a89d5

  • SHA512

    61609bbcf4b09a5feb0ba72b531687f73bb3ee1e12dd7bda6ab2a4b5caf33f39e91df7f200184b63039cd7eee2b6b95575a89f5f03850d4841861ca3f4e377b5

  • SSDEEP

    6144:tloZMNrIkd8g+EtXHkv/iD4vW2mmkrHMl9YW3X241b8e1mik4i:voZmL+EP8vW2mmkrHMl9YW3X2MXkB

Score
10/10

Malware Config

Extracted

Family

umbral

C2

https://discord.com/api/webhooks/1256897815846715535/AvBKVU2EucmaRtwFWT2pWybOZO_0KQAaWt-KOHeGe-RrtfOxVFRFXEIrZ1xFArFKPTO0

Signatures

  • Detect Umbral payload 1 IoCs
  • Umbral family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • dllmain.exe
    .exe windows:4 windows x86 arch:x86

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections