General

  • Target

    71e8f3e0b9646453d4472988b34cf168.bin

  • Size

    43.5MB

  • Sample

    240701-cqtpzatakg

  • MD5

    71e8f3e0b9646453d4472988b34cf168

  • SHA1

    8afc899197fff97a84427c7d7a15b07126bbd911

  • SHA256

    a45ea70c7d396771c6372030f9a39af27b53d87865ae931b6119d50eacab1740

  • SHA512

    946e0c377f5f39119a9baedf16ee83692a7c6d764b167535a0b0049ae604536e1ef8c6c903305d78a24c6488760853d627065c6ae81927f53655e1006098a73c

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcH+wEb:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRv

Malware Config

Targets

    • Target

      71e8f3e0b9646453d4472988b34cf168.bin

    • Size

      43.5MB

    • MD5

      71e8f3e0b9646453d4472988b34cf168

    • SHA1

      8afc899197fff97a84427c7d7a15b07126bbd911

    • SHA256

      a45ea70c7d396771c6372030f9a39af27b53d87865ae931b6119d50eacab1740

    • SHA512

      946e0c377f5f39119a9baedf16ee83692a7c6d764b167535a0b0049ae604536e1ef8c6c903305d78a24c6488760853d627065c6ae81927f53655e1006098a73c

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcH+wEb:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRv

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks