General

  • Target

    d014-9a13-4c86.exe

  • Size

    17.9MB

  • Sample

    240630-vp5d7avbkl

  • MD5

    32cfd0d80dbf54fb63c6dd5fd84b517d

  • SHA1

    9aa2737687ba0b936169a021e70f9848422b376b

  • SHA256

    af2022deb3462d47b4025847e614115f08b376371d2dfc9d8dcb78e8e174f214

  • SHA512

    4ffa13249e572d90566dc8bb1fed283e3e9b4cca52d6d81eafdfec2e0908a91e0d4ad750bbe42781e151e6b806bb5078a436f074d1bc4b0cef76e059d7ee7b72

  • SSDEEP

    393216:M+toHd5NJJl/Iu3MrNu6bC49N+ggHXxodvet/UfCZ6NoL:Mrd5zJl/Iu3MrNtb9+ggHXxEvetcKQNs

Malware Config

Targets

    • Target

      d014-9a13-4c86.exe

    • Size

      17.9MB

    • MD5

      32cfd0d80dbf54fb63c6dd5fd84b517d

    • SHA1

      9aa2737687ba0b936169a021e70f9848422b376b

    • SHA256

      af2022deb3462d47b4025847e614115f08b376371d2dfc9d8dcb78e8e174f214

    • SHA512

      4ffa13249e572d90566dc8bb1fed283e3e9b4cca52d6d81eafdfec2e0908a91e0d4ad750bbe42781e151e6b806bb5078a436f074d1bc4b0cef76e059d7ee7b72

    • SSDEEP

      393216:M+toHd5NJJl/Iu3MrNu6bC49N+ggHXxodvet/UfCZ6NoL:Mrd5zJl/Iu3MrNtb9+ggHXxEvetcKQNs

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

1
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

1
T1005

Tasks