General

  • Target

    c6df32963b817f78a6d0ed89db03a368.bin

  • Size

    29.6MB

  • Sample

    240701-dwf7havclh

  • MD5

    c6df32963b817f78a6d0ed89db03a368

  • SHA1

    77298101dd25f6cd81c31ddae2a20ea2febc44c5

  • SHA256

    0f2151ce583037b9072a039db984282f73be1e0205142af0f6b5cb3faed3628d

  • SHA512

    1a722980d08f7e4f964225c5ffc1ea79acfeb5c9a801ccc7e749f7c2483976a9c70fcf54f8e2c8a2d12348f2042a5bbac836c3564cbbb007d43dd3b6064e4564

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJx:9wYn7dX/uyv28Id5PlIQk0f

Malware Config

Targets

    • Target

      c6df32963b817f78a6d0ed89db03a368.bin

    • Size

      29.6MB

    • MD5

      c6df32963b817f78a6d0ed89db03a368

    • SHA1

      77298101dd25f6cd81c31ddae2a20ea2febc44c5

    • SHA256

      0f2151ce583037b9072a039db984282f73be1e0205142af0f6b5cb3faed3628d

    • SHA512

      1a722980d08f7e4f964225c5ffc1ea79acfeb5c9a801ccc7e749f7c2483976a9c70fcf54f8e2c8a2d12348f2042a5bbac836c3564cbbb007d43dd3b6064e4564

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJx:9wYn7dX/uyv28Id5PlIQk0f

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Discovery

Query Registry

1
T1012

Tasks