General

  • Target

    26c5fa67948d34287f3da17fb83b50eb8c3fdd725b3b631ba721fa642a9b7cd3

  • Size

    1.3MB

  • Sample

    240630-ygq4datdkh

  • MD5

    0b4d64e655a9eeeb3d1a901b9f97a8f1

  • SHA1

    3878ebeed319110a2e4b84018c9b1692a990a6e4

  • SHA256

    26c5fa67948d34287f3da17fb83b50eb8c3fdd725b3b631ba721fa642a9b7cd3

  • SHA512

    e58b69b8da4e4ce7955f328551ed3f3b59d2388b32b885296dde63c6a4aac96fce2780dcdadd7017f8a5afab6749b272283c934101e1e617fdba21c56d8c0afa

  • SSDEEP

    24576:xo5ik3NNyIOkkVEv6KusCmpvmmxDBWq8muFVquk5QhLeS7oLq8LXAU0Q:xokabPgVwkDKQESOJt

Malware Config

Targets

    • Target

      26c5fa67948d34287f3da17fb83b50eb8c3fdd725b3b631ba721fa642a9b7cd3

    • Size

      1.3MB

    • MD5

      0b4d64e655a9eeeb3d1a901b9f97a8f1

    • SHA1

      3878ebeed319110a2e4b84018c9b1692a990a6e4

    • SHA256

      26c5fa67948d34287f3da17fb83b50eb8c3fdd725b3b631ba721fa642a9b7cd3

    • SHA512

      e58b69b8da4e4ce7955f328551ed3f3b59d2388b32b885296dde63c6a4aac96fce2780dcdadd7017f8a5afab6749b272283c934101e1e617fdba21c56d8c0afa

    • SSDEEP

      24576:xo5ik3NNyIOkkVEv6KusCmpvmmxDBWq8muFVquk5QhLeS7oLq8LXAU0Q:xokabPgVwkDKQESOJt

    • Executes dropped EXE

    • Loads dropped DLL

    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Modify Registry

1
T1112

Discovery

System Information Discovery

2
T1082

Query Registry

1
T1012

Tasks