General

  • Target

    3974b6572a8a98cb09776b5aac59a22b.bin

  • Size

    34.0MB

  • Sample

    240701-b1czjascpa

  • MD5

    3974b6572a8a98cb09776b5aac59a22b

  • SHA1

    fa15c8b7bb8e02d3e514c4e43532a950e17ad4da

  • SHA256

    341ff8f5dbe70bc1acbc40cd367d2aa65f88a98375bce262d5381d3c47447460

  • SHA512

    5d5bf1615611324495d087a115bd3a1edd7a625f49f604974ee2e666348073c6147e1a79c18b01eea9bd9b473f7886357b996e6971edd4d6331a7f5eb9a8d463

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzT:9wYn7dX/uyv28Id5PlIQk0qeyOT

Malware Config

Targets

    • Target

      3974b6572a8a98cb09776b5aac59a22b.bin

    • Size

      34.0MB

    • MD5

      3974b6572a8a98cb09776b5aac59a22b

    • SHA1

      fa15c8b7bb8e02d3e514c4e43532a950e17ad4da

    • SHA256

      341ff8f5dbe70bc1acbc40cd367d2aa65f88a98375bce262d5381d3c47447460

    • SHA512

      5d5bf1615611324495d087a115bd3a1edd7a625f49f604974ee2e666348073c6147e1a79c18b01eea9bd9b473f7886357b996e6971edd4d6331a7f5eb9a8d463

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzT:9wYn7dX/uyv28Id5PlIQk0qeyOT

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks