General

  • Target

    AnyViewerSetup.exe

  • Size

    36.3MB

  • Sample

    240630-v7mbbsvdjn

  • MD5

    199f287b81b00d54ec6e12c313bbdc4e

  • SHA1

    25ff04330d5a1fafae592f0d07e9e6ecfc61db60

  • SHA256

    334ec9e7d937c42e8ef12f9d4ec90862ecc5410c06442393a38390b34886aa59

  • SHA512

    1006d0c84c5f8bdcf50670958f24a7d0a3d0dff54d620d1dcc5d9e057269dbc506a7e622172ab673aed108b4e0ab0e7569fc89898e335c74d2c61ca6e354f16a

  • SSDEEP

    786432:e0ea8KPO0BEreQ/dyD7VVZIXPMA/h9rWsyd6d0z1CojZSd23Y9z9o2VRrtp:ePKP3mJ/8D7hkj/b1ydFZjZS59BLpp

Malware Config

Targets

    • Target

      AnyViewerSetup.exe

    • Size

      36.3MB

    • MD5

      199f287b81b00d54ec6e12c313bbdc4e

    • SHA1

      25ff04330d5a1fafae592f0d07e9e6ecfc61db60

    • SHA256

      334ec9e7d937c42e8ef12f9d4ec90862ecc5410c06442393a38390b34886aa59

    • SHA512

      1006d0c84c5f8bdcf50670958f24a7d0a3d0dff54d620d1dcc5d9e057269dbc506a7e622172ab673aed108b4e0ab0e7569fc89898e335c74d2c61ca6e354f16a

    • SSDEEP

      786432:e0ea8KPO0BEreQ/dyD7VVZIXPMA/h9rWsyd6d0z1CojZSd23Y9z9o2VRrtp:ePKP3mJ/8D7hkj/b1ydFZjZS59BLpp

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

3
T1012

System Information Discovery

3
T1082

Collection

Data from Local System

1
T1005

Tasks