General
-
Target
a2e3023d37322d8063e0fcf62d4e3bc57e36f97ba394960bcfbcea543b1355fb
-
Size
767KB
-
Sample
240630-w238bsvgpn
-
MD5
96231ea3e5180858d217f6d07492d54c
-
SHA1
ecf185fca21c97fface0d2101d06e50a1a42f8e7
-
SHA256
a2e3023d37322d8063e0fcf62d4e3bc57e36f97ba394960bcfbcea543b1355fb
-
SHA512
8182b938c2341fbbd65499b8f823731c7fea05e59ad9fe8e5eb145b284c220b911061b3a03e2dc78b2b1d7110b30b575f60331a43062effa6940f9933b5165c1
-
SSDEEP
12288:X1V4L4PCtGDtlLJgsGoT6gYAMkZ6XlwAcMs+50tgAakT7hs5fDDbbjmh8Q0uRgIe:X1VUQDtlLJg3or6XKAsCIRVbCA92
Static task
static1
Behavioral task
behavioral1
Sample
a2e3023d37322d8063e0fcf62d4e3bc57e36f97ba394960bcfbcea543b1355fb.exe
Resource
win7-20240221-en
Malware Config
Extracted
sality
http://89.119.67.154/testo5/
http://kukutrustnet777.info/home.gif
http://kukutrustnet888.info/home.gif
http://kukutrustnet987.info/home.gif
Targets
-
-
Target
a2e3023d37322d8063e0fcf62d4e3bc57e36f97ba394960bcfbcea543b1355fb
-
Size
767KB
-
MD5
96231ea3e5180858d217f6d07492d54c
-
SHA1
ecf185fca21c97fface0d2101d06e50a1a42f8e7
-
SHA256
a2e3023d37322d8063e0fcf62d4e3bc57e36f97ba394960bcfbcea543b1355fb
-
SHA512
8182b938c2341fbbd65499b8f823731c7fea05e59ad9fe8e5eb145b284c220b911061b3a03e2dc78b2b1d7110b30b575f60331a43062effa6940f9933b5165c1
-
SSDEEP
12288:X1V4L4PCtGDtlLJgsGoT6gYAMkZ6XlwAcMs+50tgAakT7hs5fDDbbjmh8Q0uRgIe:X1VUQDtlLJg3or6XKAsCIRVbCA92
-
Modifies firewall policy service
-
Downloads MZ/PE file
-
MITRE ATT&CK Matrix ATT&CK v13
Privilege Escalation
Create or Modify System Process
1Windows Service
1Abuse Elevation Control Mechanism
1Bypass User Account Control
1