General

  • Target

    d106b840ab48dd55ade2dd9b56c388a9.bin

  • Size

    43.5MB

  • Sample

    240701-d5ttysybrp

  • MD5

    d106b840ab48dd55ade2dd9b56c388a9

  • SHA1

    833e2514f28b164b73ca3739c93b565e5eb537ce

  • SHA256

    57a788eedfe9a73a558cf292f9e4702287245168f0f0e5d217120bf17fcf830c

  • SHA512

    7ba36dbb49a32f732b68826434fc8cc87278e558874941db0efb17b1a30d44a11d5ee167c544293f748076648d59602e85f02344959aafac40c46f42d5c67b0f

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcH+wE8:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrR4

Malware Config

Targets

    • Target

      d106b840ab48dd55ade2dd9b56c388a9.bin

    • Size

      43.5MB

    • MD5

      d106b840ab48dd55ade2dd9b56c388a9

    • SHA1

      833e2514f28b164b73ca3739c93b565e5eb537ce

    • SHA256

      57a788eedfe9a73a558cf292f9e4702287245168f0f0e5d217120bf17fcf830c

    • SHA512

      7ba36dbb49a32f732b68826434fc8cc87278e558874941db0efb17b1a30d44a11d5ee167c544293f748076648d59602e85f02344959aafac40c46f42d5c67b0f

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcH+wE8:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrR4

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks