General

  • Target

    de1342e1344d5583d2f358b1dd0c7a344390593549d6c7df07017a2154cfa8cd

  • Size

    98KB

  • Sample

    240701-d6k87sverd

  • MD5

    0f2ae59a2da1372cb119ac97ea1480cd

  • SHA1

    6c448860d8c465107c25b4c0a28d0d3021f83042

  • SHA256

    de1342e1344d5583d2f358b1dd0c7a344390593549d6c7df07017a2154cfa8cd

  • SHA512

    b6286dd5ae88ba980049ff729c1981dc4feb80f85cd3c35b359dd9de2f656ef26182e53a20b0f641a15990d5df2b3e1a7a87e1a016f42ceae90e23530d73230c

  • SSDEEP

    3072:EMS2hV9QLZ19CROWeSw1w/WcPa2EGeFKPD375lHzpa1P:EMS2aURGS0eWcPa2EGeYr75lHzpaF

Score
10/10

Malware Config

Targets

    • Target

      de1342e1344d5583d2f358b1dd0c7a344390593549d6c7df07017a2154cfa8cd

    • Size

      98KB

    • MD5

      0f2ae59a2da1372cb119ac97ea1480cd

    • SHA1

      6c448860d8c465107c25b4c0a28d0d3021f83042

    • SHA256

      de1342e1344d5583d2f358b1dd0c7a344390593549d6c7df07017a2154cfa8cd

    • SHA512

      b6286dd5ae88ba980049ff729c1981dc4feb80f85cd3c35b359dd9de2f656ef26182e53a20b0f641a15990d5df2b3e1a7a87e1a016f42ceae90e23530d73230c

    • SSDEEP

      3072:EMS2hV9QLZ19CROWeSw1w/WcPa2EGeFKPD375lHzpa1P:EMS2aURGS0eWcPa2EGeYr75lHzpaF

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks