General

  • Target

    e135042aec0f267d28ea2e6d153d3cf20a754f6520439abfdc76d8d35e3d7af6

  • Size

    91KB

  • Sample

    240701-d94vqavfra

  • MD5

    31c8a9af54080ad7b446a7ecc4073c0d

  • SHA1

    fb613f8ddeba8240df18199f49f614e4cde370ae

  • SHA256

    e135042aec0f267d28ea2e6d153d3cf20a754f6520439abfdc76d8d35e3d7af6

  • SHA512

    fc5a9140519b50e902cbb2596408953b9009311e61177f3409f30ec5782b67c3aeaf6fbd7512fd6d7b5856d16a7a19150798be096c774138505c84e4700f3e72

  • SSDEEP

    1536:VgZi0tEBOFsLCDwtng//ETEfsKp8NjBAg5c/6lLBsLnVLdGUHyNwtN4/nLLVaBlX:VCioEAswwG0YfsKp8NVAg506lLBsLnV1

Score
10/10

Malware Config

Targets

    • Target

      e135042aec0f267d28ea2e6d153d3cf20a754f6520439abfdc76d8d35e3d7af6

    • Size

      91KB

    • MD5

      31c8a9af54080ad7b446a7ecc4073c0d

    • SHA1

      fb613f8ddeba8240df18199f49f614e4cde370ae

    • SHA256

      e135042aec0f267d28ea2e6d153d3cf20a754f6520439abfdc76d8d35e3d7af6

    • SHA512

      fc5a9140519b50e902cbb2596408953b9009311e61177f3409f30ec5782b67c3aeaf6fbd7512fd6d7b5856d16a7a19150798be096c774138505c84e4700f3e72

    • SSDEEP

      1536:VgZi0tEBOFsLCDwtng//ETEfsKp8NjBAg5c/6lLBsLnVLdGUHyNwtN4/nLLVaBlX:VCioEAswwG0YfsKp8NVAg506lLBsLnV1

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks