General

  • Target

    6fxRmw1k.exe

  • Size

    15.8MB

  • Sample

    240701-1zs2sswfnl

  • MD5

    4e8f9d3ff9bef01703b1cfb6fcd5bed8

  • SHA1

    1423844e3107eafe1a23cc9b55305ffc1843cc2f

  • SHA256

    ea20425e0ec34bea58cc32c62f0f5dfb03772aa4787f05b647d30dca153941b9

  • SHA512

    16c06bcda2cd4bc361171ba2ecc3f0c76c1757bc32f70f56db70ca16e6d2c7bab73c90f127575f85899dbe9fda9ca115cc9e1cfea1d6413f267b6e5c72f4120c

  • SSDEEP

    393216:KECIFPbxdP7YwIMTXZKkrmCKrru38xHI9Z+8TwvpBDX:KEC8XPc/MTXZKkArS8xHIyew7

Malware Config

Targets

    • Target

      6fxRmw1k.exe

    • Size

      15.8MB

    • MD5

      4e8f9d3ff9bef01703b1cfb6fcd5bed8

    • SHA1

      1423844e3107eafe1a23cc9b55305ffc1843cc2f

    • SHA256

      ea20425e0ec34bea58cc32c62f0f5dfb03772aa4787f05b647d30dca153941b9

    • SHA512

      16c06bcda2cd4bc361171ba2ecc3f0c76c1757bc32f70f56db70ca16e6d2c7bab73c90f127575f85899dbe9fda9ca115cc9e1cfea1d6413f267b6e5c72f4120c

    • SSDEEP

      393216:KECIFPbxdP7YwIMTXZKkrmCKrru38xHI9Z+8TwvpBDX:KEC8XPc/MTXZKkArS8xHIyew7

    • Deletes NTFS Change Journal

      The USN change journal is a persistent log of all changes made to local files used by Windows Server systems.

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Server Software Component: Terminal Services DLL

    • Stops running service(s)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

    • Drops file in System32 directory

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks