General

  • Target

    ded5e8f88df5b691bf260cd7bd93e64ea3a9190d8cf436aceadb529fe71cec50

  • Size

    88KB

  • Sample

    240701-d7y7fsvfkf

  • MD5

    2da19abb8c240fdf112e15db5c382d07

  • SHA1

    08639292e60a14839dc8b358e5af86b128e1fd28

  • SHA256

    ded5e8f88df5b691bf260cd7bd93e64ea3a9190d8cf436aceadb529fe71cec50

  • SHA512

    88fea8fb2df2c663f68894f01c18668dd3bb9e21ca6fb801917b9cbea67616cb3bd7bc07b2d354855778b09c8e25d1571408acf943cfbe8ae54bb927380f01de

  • SSDEEP

    1536:RGq04a1oLTnTEEtC6lFCcsKME4q/mp/Ws7iFyAvQpqqXRp4rnouy8L:cH4iIlF2DBWYiFy7oqhp4zoutL

Score
10/10

Malware Config

Targets

    • Target

      ded5e8f88df5b691bf260cd7bd93e64ea3a9190d8cf436aceadb529fe71cec50

    • Size

      88KB

    • MD5

      2da19abb8c240fdf112e15db5c382d07

    • SHA1

      08639292e60a14839dc8b358e5af86b128e1fd28

    • SHA256

      ded5e8f88df5b691bf260cd7bd93e64ea3a9190d8cf436aceadb529fe71cec50

    • SHA512

      88fea8fb2df2c663f68894f01c18668dd3bb9e21ca6fb801917b9cbea67616cb3bd7bc07b2d354855778b09c8e25d1571408acf943cfbe8ae54bb927380f01de

    • SSDEEP

      1536:RGq04a1oLTnTEEtC6lFCcsKME4q/mp/Ws7iFyAvQpqqXRp4rnouy8L:cH4iIlF2DBWYiFy7oqhp4zoutL

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks