General

  • Target

    vivo 2024 - Материалы.rar

  • Size

    58.5MB

  • Sample

    240630-vpgccs1dkb

  • MD5

    7adcf82dde9e8c8b49b7a3e9f0f70954

  • SHA1

    c6b7b816ff0728dbb1207fa6504961082a52eb1b

  • SHA256

    2f1caea4b57ec875eeabcf3d25c32a559564be15147b1b5ce85522b1fb6c78f0

  • SHA512

    38471fc477b0c4464e680c9d9ba5c6ba654f4b1d1a55c29e58301d295c9e962dae822add4795f18309ba80cccb95bf11c8013b0ebceee34bea183f9e25ad2cf4

  • SSDEEP

    1572864:vYrZeq4w4pdErotxYu0ORdww+jQnT44dFar:vuEK4p0qEOowpnT43r

Malware Config

Targets

    • Target

      vivo Договор на оказание рекламных услуг.scr

    • Size

      55.0MB

    • MD5

      70eac30776d13a02e4b6a5e6963c52b9

    • SHA1

      b7deafce3ff7d7252ed29d6f508a49a6d1b63504

    • SHA256

      b563a0d625aa148c992413947b2d3ceae678c27fd6d1eadf8e9eb3e10d5206f5

    • SHA512

      fab91b7ba11ff12d2bfa2f2d2c260fa15a8b1543c108c3d81337a74d3933b7c9dc73b866ce3f294414aab031d646c52ea86251fe020501c11ff50ae2cc78a391

    • SSDEEP

      196608:8xGxCrar4+WnAL3fljyBTEbAdoaU7wtq9oaqN:VxCGUnAL3OEEdou20N

    • Rhadamanthys

      Rhadamanthys is an info stealer written in C++ first seen in August 2022.

    • Suspicious use of NtCreateUserProcessOtherParentProcess

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks