General

  • Target

    protected_sacrifice.exe

  • Size

    8.5MB

  • Sample

    240701-cn5z8ashra

  • MD5

    5e04815f52a1ab2dc4b18f293e542ddd

  • SHA1

    a8c9c6e0644523668ade7427477811b843b19187

  • SHA256

    60dc3e25f1cfac87bc4827d8379606a450e358767efcc79b0bf460c006dc57a7

  • SHA512

    d17c89610b369f06646cbdba1ee874810b038d81d0f66be540a97f4a3e92afb49a26af99cdfa34017db2002375af6ff1c37c149c342a213dcb892ba7542b10cc

  • SSDEEP

    196608:u0duRAkHBahImnxr5y0u9HYbDbZxgZ6KvQ8QflFGS6C:u0s6khaLyKbDbZxgZrOflo

Score
7/10

Malware Config

Targets

    • Target

      protected_sacrifice.exe

    • Size

      8.5MB

    • MD5

      5e04815f52a1ab2dc4b18f293e542ddd

    • SHA1

      a8c9c6e0644523668ade7427477811b843b19187

    • SHA256

      60dc3e25f1cfac87bc4827d8379606a450e358767efcc79b0bf460c006dc57a7

    • SHA512

      d17c89610b369f06646cbdba1ee874810b038d81d0f66be540a97f4a3e92afb49a26af99cdfa34017db2002375af6ff1c37c149c342a213dcb892ba7542b10cc

    • SSDEEP

      196608:u0duRAkHBahImnxr5y0u9HYbDbZxgZ6KvQ8QflFGS6C:u0s6khaLyKbDbZxgZrOflo

    Score
    7/10
    • VMProtect packed file

      Detects executables packed with VMProtect commercial packer.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix

Tasks