General

  • Target

    b1ce307191b9b029301d5c896e6d8efebb8d75b4db6993a0062759b0065d88e0

  • Size

    2.1MB

  • Sample

    240630-x7gryswgmn

  • MD5

    5a36f877c1754ec1b28965da122e45a2

  • SHA1

    bef9a0e53e7dc23cbcd935edefc11e64000661ff

  • SHA256

    b1ce307191b9b029301d5c896e6d8efebb8d75b4db6993a0062759b0065d88e0

  • SHA512

    a1066c262b3534c4bf0da80b2befa8860812ca4b9df5628f1187b329847d0baa31d714284c934ae46d9ba26af8d508e56876f285b886fb0c3f14726822ddb383

  • SSDEEP

    49152:97CHEZXbb2PHs+KEpU3coSCglR/GQeTRF:0EFv2PTKEpJo/cR/GFD

Malware Config

Targets

    • Target

      b1ce307191b9b029301d5c896e6d8efebb8d75b4db6993a0062759b0065d88e0

    • Size

      2.1MB

    • MD5

      5a36f877c1754ec1b28965da122e45a2

    • SHA1

      bef9a0e53e7dc23cbcd935edefc11e64000661ff

    • SHA256

      b1ce307191b9b029301d5c896e6d8efebb8d75b4db6993a0062759b0065d88e0

    • SHA512

      a1066c262b3534c4bf0da80b2befa8860812ca4b9df5628f1187b329847d0baa31d714284c934ae46d9ba26af8d508e56876f285b886fb0c3f14726822ddb383

    • SSDEEP

      49152:97CHEZXbb2PHs+KEpU3coSCglR/GQeTRF:0EFv2PTKEpJo/cR/GFD

    • Ramnit

      Ramnit is a versatile family that holds viruses, worms, and Trojans.

    • Deletes itself

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks