General

  • Target

    Rank1.exe

  • Size

    9.9MB

  • Sample

    240630-v3qsysvcnp

  • MD5

    3deac91b51a5cee8828461697090a6d0

  • SHA1

    941986b1f4dd7cf7d851e2ad956e3f5811eeb944

  • SHA256

    a70e7b1646a178d7457ac58dc6a12b5401ee55de6d691614aaa9ca8b1046e154

  • SHA512

    ee3f9eb2b00a12cf46391b20489d9940ed0645ef8b6391d33008c611cc38d18795123f0331b7f4365a3f64d27073d21dc460696374987d1785ef06d42a9617b0

  • SSDEEP

    196608:og1RtndQmRJ8dA6lxuVaycBIGpER/1q3+dgSVe30W8/LaZacqGSeZ:9tndQuslxl9uq3+d9VekW8enZ

Malware Config

Targets

    • Target

      Rank1.exe

    • Size

      9.9MB

    • MD5

      3deac91b51a5cee8828461697090a6d0

    • SHA1

      941986b1f4dd7cf7d851e2ad956e3f5811eeb944

    • SHA256

      a70e7b1646a178d7457ac58dc6a12b5401ee55de6d691614aaa9ca8b1046e154

    • SHA512

      ee3f9eb2b00a12cf46391b20489d9940ed0645ef8b6391d33008c611cc38d18795123f0331b7f4365a3f64d27073d21dc460696374987d1785ef06d42a9617b0

    • SSDEEP

      196608:og1RtndQmRJ8dA6lxuVaycBIGpER/1q3+dgSVe30W8/LaZacqGSeZ:9tndQuslxl9uq3+d9VekW8enZ

    Score
    8/10
    • Drops file in Drivers directory

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Loads dropped DLL

    • Modifies file permissions

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

Defense Evasion

File and Directory Permissions Modification

1
T1222

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Discovery

Query Registry

2
T1012

System Information Discovery

4
T1082

Remote System Discovery

1
T1018

Tasks