General

  • Target

    SecuriteInfo.com.Win64.TrojanX-gen.2933.9379.exe

  • Size

    11.6MB

  • Sample

    240630-ze99xaybjm

  • MD5

    7b3f86198fc47ee9e67c1d8c21983e27

  • SHA1

    a7aedf26db9589249061062b2ec416f6d870d90c

  • SHA256

    e039f173ff60e01ef93b5c26b5872eb45f0cdbd9997b52d8eba7ed216da3f4df

  • SHA512

    0051ef056da1d6146859fccf746857fe58b4c69fc5b9194a4b0dfc111c11c999c61134d0bbb0865cefcd11c049b0ff82beebd9d95608b7c4f6febcf9d2eec1cc

  • SSDEEP

    196608:1geUq7E5uQdhBhLgJ/vIxOYT3Lc7vHnDqnHqMGPS+r1okHWQTps+SbnN4Lps8W+x:VEg6lgJXIx7T34bHDqnKMASu19WAcbn0

Malware Config

Targets

    • Target

      SecuriteInfo.com.Win64.TrojanX-gen.2933.9379.exe

    • Size

      11.6MB

    • MD5

      7b3f86198fc47ee9e67c1d8c21983e27

    • SHA1

      a7aedf26db9589249061062b2ec416f6d870d90c

    • SHA256

      e039f173ff60e01ef93b5c26b5872eb45f0cdbd9997b52d8eba7ed216da3f4df

    • SHA512

      0051ef056da1d6146859fccf746857fe58b4c69fc5b9194a4b0dfc111c11c999c61134d0bbb0865cefcd11c049b0ff82beebd9d95608b7c4f6febcf9d2eec1cc

    • SSDEEP

      196608:1geUq7E5uQdhBhLgJ/vIxOYT3Lc7vHnDqnHqMGPS+r1okHWQTps+SbnN4Lps8W+x:VEg6lgJXIx7T34bHDqnKMASu19WAcbn0

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Discovery

Query Registry

2
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

2
T1082

Tasks