General

  • Target

    winnt64.exe

  • Size

    188KB

  • Sample

    240701-cwm5datbqa

  • MD5

    aa992d93467882ff211f211495e6c545

  • SHA1

    75a1a182af719168b9ca7b9c42282b997f82d443

  • SHA256

    dadd54e1c3b0496d3a49e112da7c3d71255037df9ba27b890131330b42eabf88

  • SHA512

    54d07b5f123b20128459de04694ed295275498c646fef596830c2c98ff1a8fa4741c95ce72be6d59a713fc6d7d7365c4f13eace2ed6bf357ebef44885b882d5d

  • SSDEEP

    3072:vV3J6kkt5h1X+HqTi0BW69hd1MMdxPe9N9uA0/+hL9TBfnPTYEbXEC+gwNDF/Kjs:it5hBPi0BW69hd1MMdxPe9N9uA069TBk

Malware Config

Targets

    • Target

      winnt64.exe

    • Size

      188KB

    • MD5

      aa992d93467882ff211f211495e6c545

    • SHA1

      75a1a182af719168b9ca7b9c42282b997f82d443

    • SHA256

      dadd54e1c3b0496d3a49e112da7c3d71255037df9ba27b890131330b42eabf88

    • SHA512

      54d07b5f123b20128459de04694ed295275498c646fef596830c2c98ff1a8fa4741c95ce72be6d59a713fc6d7d7365c4f13eace2ed6bf357ebef44885b882d5d

    • SSDEEP

      3072:vV3J6kkt5h1X+HqTi0BW69hd1MMdxPe9N9uA0/+hL9TBfnPTYEbXEC+gwNDF/Kjs:it5hBPi0BW69hd1MMdxPe9N9uA069TBk

    • Possible privilege escalation attempt

    • Modifies file permissions

    • File and Directory Permissions Modification: Windows File and Directory Permissions Modification

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

File and Directory Permissions Modification

2
T1222

Windows File and Directory Permissions Modification

1
T1222.001

Discovery

System Information Discovery

2
T1082

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

Tasks