General

  • Target

    TERESPAIR.exe

  • Size

    551KB

  • Sample

    240701-ctd4patarb

  • MD5

    0ffccbd12475d9082cf307ad70739bdc

  • SHA1

    3357a844ae038543844e622839167e7ff1360474

  • SHA256

    4c291a0e441b43a6d0bb77f5038ca736276e735196349abb6e9d4c7cc3fd4dc5

  • SHA512

    7d8893b8082faf6dee334959f602c5e81192982238ce5dfd52210f7db48c73fe5ad952860f845404b7c369e3be11d3c6bc0cab2cacab993632211a5e599559ee

  • SSDEEP

    12288:Scv0NTIx0stUF2jL2DBzvksvkyRQ72KGNxJLACRC/q9:ScvkTIxxUFT9TvkG7lJsCUy9

Malware Config

Targets

    • Target

      TERESPAIR.exe

    • Size

      551KB

    • MD5

      0ffccbd12475d9082cf307ad70739bdc

    • SHA1

      3357a844ae038543844e622839167e7ff1360474

    • SHA256

      4c291a0e441b43a6d0bb77f5038ca736276e735196349abb6e9d4c7cc3fd4dc5

    • SHA512

      7d8893b8082faf6dee334959f602c5e81192982238ce5dfd52210f7db48c73fe5ad952860f845404b7c369e3be11d3c6bc0cab2cacab993632211a5e599559ee

    • SSDEEP

      12288:Scv0NTIx0stUF2jL2DBzvksvkyRQ72KGNxJLACRC/q9:ScvkTIxxUFT9TvkG7lJsCUy9

    • UAC bypass

    • Modifies boot configuration data using bcdedit

    • Possible privilege escalation attempt

    • Modifies file permissions

    • Modifies system executable filetype association

    • Adds Run key to start application

    • File and Directory Permissions Modification: Windows File and Directory Permissions Modification

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Abuse Elevation Control Mechanism

1
T1548

Bypass User Account Control

1
T1548.002

Impair Defenses

1
T1562

Disable or Modify Tools

1
T1562.001

Modify Registry

3
T1112

File and Directory Permissions Modification

2
T1222

Windows File and Directory Permissions Modification

1
T1222.001

Discovery

System Information Discovery

1
T1082

Impact

Inhibit System Recovery

1
T1490

Tasks