General

  • Target

    2024-06-30_9930184bfe3f2a6e964ebbfcececd585_bkransomware

  • Size

    520KB

  • Sample

    240630-ysdbnaxcpm

  • MD5

    9930184bfe3f2a6e964ebbfcececd585

  • SHA1

    31604a135255898f949b876bd8b3d0be697a5ebe

  • SHA256

    1969764d05a47d65afe229f2a52b5e9349e0dc0c40e44f63fad24d50f9934e76

  • SHA512

    4b74abd86d0133e0764a8bd7689375a6e4fc9765496ecbb9f4484d371064f158325c52e732a29a3aa40897cc27b1ca412fd60261c3b6e7c620a4b70cd216a472

  • SSDEEP

    6144:YoyZmTAsfJFakxaLjcMkc0Cax1PmgGp6bYA0w601+dNT9/0626ASkVOAFAo9WUZn:YoyIJsMPrP6p6bYboEdNLo9R3rz

Malware Config

Extracted

Family

sality

C2

http://89.119.67.154/testo5/

http://kukutrustnet777.info/home.gif

http://kukutrustnet888.info/home.gif

http://kukutrustnet987.info/home.gif

Targets

    • Target

      2024-06-30_9930184bfe3f2a6e964ebbfcececd585_bkransomware

    • Size

      520KB

    • MD5

      9930184bfe3f2a6e964ebbfcececd585

    • SHA1

      31604a135255898f949b876bd8b3d0be697a5ebe

    • SHA256

      1969764d05a47d65afe229f2a52b5e9349e0dc0c40e44f63fad24d50f9934e76

    • SHA512

      4b74abd86d0133e0764a8bd7689375a6e4fc9765496ecbb9f4484d371064f158325c52e732a29a3aa40897cc27b1ca412fd60261c3b6e7c620a4b70cd216a472

    • SSDEEP

      6144:YoyZmTAsfJFakxaLjcMkc0Cax1PmgGp6bYA0w601+dNT9/0626ASkVOAFAo9WUZn:YoyIJsMPrP6p6bYboEdNLo9R3rz

    • Modifies firewall policy service

    • Sality

      Sality is backdoor written in C++, first discovered in 2003.

    • UAC bypass

    • Windows security bypass

    • Detects executables packed with Sality Polymorphic Code Generator or Simple Poly Engine or Sality

    • UPX dump on OEP (original entry point)

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Windows security modification

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Defense Evasion

Modify Registry

5
T1112

Impair Defenses

4
T1562

Disable or Modify Tools

3
T1562.001

Disable or Modify System Firewall

1
T1562.004

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Discovery

System Information Discovery

1
T1082

Tasks