General

  • Target

    SparkClicker.zip

  • Size

    6.8MB

  • Sample

    240630-zx1s7avhna

  • MD5

    a67d2dc8147f549be624d81f75438efe

  • SHA1

    7dc0de0e35ed9ca838d3dfb653d16719a0c16ff8

  • SHA256

    10a117befd88193d2c0d714b8d67c6583b1322e978e7eda4c8db9e40405a5d80

  • SHA512

    0c24142e08dcf3da81400ac39998ae642e241fe2439700142919cde06c6b6617448bb119d6b97bd33c15b5dcfb06d9331233b9fef332a820b5ec3f889e36a672

  • SSDEEP

    98304:zWlTCuzoPwnYMdelKwhTiJJQQhC1PS61qEMqzy+XzfB0CeR43DvgtsveIVlSBWl9:GTCq1GUJec61BMqbp0Ch3ZeI2bQHLFvd

Score
7/10

Malware Config

Targets

    • Target

      SparkClicker.zip

    • Size

      6.8MB

    • MD5

      a67d2dc8147f549be624d81f75438efe

    • SHA1

      7dc0de0e35ed9ca838d3dfb653d16719a0c16ff8

    • SHA256

      10a117befd88193d2c0d714b8d67c6583b1322e978e7eda4c8db9e40405a5d80

    • SHA512

      0c24142e08dcf3da81400ac39998ae642e241fe2439700142919cde06c6b6617448bb119d6b97bd33c15b5dcfb06d9331233b9fef332a820b5ec3f889e36a672

    • SSDEEP

      98304:zWlTCuzoPwnYMdelKwhTiJJQQhC1PS61qEMqzy+XzfB0CeR43DvgtsveIVlSBWl9:GTCq1GUJec61BMqbp0Ch3ZeI2bQHLFvd

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks