General
-
Target
MainC-razy.exe
-
Size
18.6MB
-
Sample
240630-vr7mbs1dmh
-
MD5
ee0856acfae5be20b38ea85315720cb2
-
SHA1
e45a3bfae79c9bda70479f5d3addad4ceea44423
-
SHA256
58337239098c01aca77aa8b4e7768ff2865400b802f3f3381fc38f8f5e30c70c
-
SHA512
7c79509309e229bb66ffcfb22853ed8a13fccac4123decb81898ee55f67643df1cb8dfe92a7a49094b3984b694a47fcb512d5d4d54e7f04440c076d5149f9e16
-
SSDEEP
393216:eEjNaf4lx6fuKIx5ndL01+l+uq+VvbW+eGQRXMTozGxu8C0ibftJXMu9:LjNu4lk3IxRR01+l+uqgvbW+e5Raoztx
Static task
static1
Behavioral task
behavioral1
Sample
MainC-razy.exe
Resource
win7-20240611-en
Malware Config
Targets
-
-
Target
MainC-razy.exe
-
Size
18.6MB
-
MD5
ee0856acfae5be20b38ea85315720cb2
-
SHA1
e45a3bfae79c9bda70479f5d3addad4ceea44423
-
SHA256
58337239098c01aca77aa8b4e7768ff2865400b802f3f3381fc38f8f5e30c70c
-
SHA512
7c79509309e229bb66ffcfb22853ed8a13fccac4123decb81898ee55f67643df1cb8dfe92a7a49094b3984b694a47fcb512d5d4d54e7f04440c076d5149f9e16
-
SSDEEP
393216:eEjNaf4lx6fuKIx5ndL01+l+uq+VvbW+eGQRXMTozGxu8C0ibftJXMu9:LjNu4lk3IxRR01+l+uqgvbW+e5Raoztx
-
Identifies VirtualBox via ACPI registry values (likely anti-VM)
-
Checks BIOS information in registry
BIOS information is often read in order to detect sandboxing environments.
-
Executes dropped EXE
-
Loads dropped DLL
-
Suspicious use of NtSetInformationThreadHideFromDebugger
-