General

  • Target

    无害.exe

  • Size

    5.6MB

  • Sample

    240701-dlkryathpc

  • MD5

    eb08619ed85a31118a80ce0a2f73f25f

  • SHA1

    4289df26068458def91c876933e0483867625b2b

  • SHA256

    f775611b5d45d3c13217c30f3792963894ecf0726a554188e5e2ee72077e6939

  • SHA512

    b8f32587867025e11c6af73c8c3c7ba8f0ec2966cbd2a702240ab26c789ff791475d753ce53114d4c07dc0e2b2c79deba7ae1752d8ccca1ba6337d4a468e3fb0

  • SSDEEP

    98304:F3AszIKgNQbnhi1ZKUZWFCGFR62sn+s0eFyVJPJuyacAlKWjR9qw4H9U:F3jzIRi1S+LFR6DZwrPJuplKWvgW

Malware Config

Targets

    • Target

      无害.exe

    • Size

      5.6MB

    • MD5

      eb08619ed85a31118a80ce0a2f73f25f

    • SHA1

      4289df26068458def91c876933e0483867625b2b

    • SHA256

      f775611b5d45d3c13217c30f3792963894ecf0726a554188e5e2ee72077e6939

    • SHA512

      b8f32587867025e11c6af73c8c3c7ba8f0ec2966cbd2a702240ab26c789ff791475d753ce53114d4c07dc0e2b2c79deba7ae1752d8ccca1ba6337d4a468e3fb0

    • SSDEEP

      98304:F3AszIKgNQbnhi1ZKUZWFCGFR62sn+s0eFyVJPJuyacAlKWjR9qw4H9U:F3jzIRi1S+LFR6DZwrPJuplKWvgW

    • AgentTesla

      Agent Tesla is a remote access tool (RAT) written in visual basic.

    • AgentTesla payload

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Drops file in System32 directory

    • Sets desktop wallpaper using registry

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Modify Registry

1
T1112

Discovery

Query Registry

4
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

4
T1082

Impact

Defacement

1
T1491

Tasks