General

  • Target

    roblox cheat.exe

  • Size

    13.3MB

  • Sample

    240630-naszaawhqa

  • MD5

    8a7152ffede480f64cc5eabc42d2b363

  • SHA1

    e5bc1f7e950197834be927bd889545a516a766f6

  • SHA256

    e55dc8cbe7a1c924ad0dc323608dee0bed109ac7b7498fa7f47566ad9640126f

  • SHA512

    9d2fd8bbebc01d2acfe6e47b85a18ce39efd00cfefa1af062d58c56c24ad2c81164a9a7761dcbe39a9df36eda08652ec2f0328ed76ddc426a7941969a289fa5d

  • SSDEEP

    196608:ZqwxqxWqsDrnZS3ZuGDMYpCbj8ZVQqJHZbLgVDmFG5fxljAsO8bzuw5G0GIlyVuW:8yw3oGJpCvQbdUmFQljtGfIgkPySP6J

Malware Config

Targets

    • Target

      roblox cheat.exe

    • Size

      13.3MB

    • MD5

      8a7152ffede480f64cc5eabc42d2b363

    • SHA1

      e5bc1f7e950197834be927bd889545a516a766f6

    • SHA256

      e55dc8cbe7a1c924ad0dc323608dee0bed109ac7b7498fa7f47566ad9640126f

    • SHA512

      9d2fd8bbebc01d2acfe6e47b85a18ce39efd00cfefa1af062d58c56c24ad2c81164a9a7761dcbe39a9df36eda08652ec2f0328ed76ddc426a7941969a289fa5d

    • SSDEEP

      196608:ZqwxqxWqsDrnZS3ZuGDMYpCbj8ZVQqJHZbLgVDmFG5fxljAsO8bzuw5G0GIlyVuW:8yw3oGJpCvQbdUmFQljtGfIgkPySP6J

    • DcRat

      DarkCrystal(DC) is a new .NET RAT active since June 2019 capable of loading additional plugins.

    • DCRat payload

      Detects payload of DCRat, commonly dropped by NSIS installers.

    • Disables RegEdit via registry modification

    • Disables Task Manager via registry modification

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Sets desktop wallpaper using registry

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

2
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

3
T1082

Peripheral Device Discovery

1
T1120

Impact

Defacement

1
T1491

Tasks