General

  • Target

    ef2229a6d82c9d91d1b92a5a91c5a0fc5a9e1ea89cc6ceb3d6c28657a7503579

  • Size

    24KB

  • Sample

    240701-e1sxjawdrb

  • MD5

    54f95fe164b62f4f46f8548c557f4005

  • SHA1

    f3a1ed8d1562a73943249eabf1a61912cb7db577

  • SHA256

    ef2229a6d82c9d91d1b92a5a91c5a0fc5a9e1ea89cc6ceb3d6c28657a7503579

  • SHA512

    b85fac0c32884cbb025d14b071ab9fd1f92723da47504554e0cfcd0273306ff6ff04478212dfd71bb3c18c1945d6dea3b3de084f9ade5cc3b0d597664fcd7c3a

  • SSDEEP

    384:UATttSPw84JRFnYJz7sto9KJzq98kENZ7wCMoYUgY:BEw84DJ3om298ECMoBgY

Score
10/10
upx

Malware Config

Targets

    • Target

      ef2229a6d82c9d91d1b92a5a91c5a0fc5a9e1ea89cc6ceb3d6c28657a7503579

    • Size

      24KB

    • MD5

      54f95fe164b62f4f46f8548c557f4005

    • SHA1

      f3a1ed8d1562a73943249eabf1a61912cb7db577

    • SHA256

      ef2229a6d82c9d91d1b92a5a91c5a0fc5a9e1ea89cc6ceb3d6c28657a7503579

    • SHA512

      b85fac0c32884cbb025d14b071ab9fd1f92723da47504554e0cfcd0273306ff6ff04478212dfd71bb3c18c1945d6dea3b3de084f9ade5cc3b0d597664fcd7c3a

    • SSDEEP

      384:UATttSPw84JRFnYJz7sto9KJzq98kENZ7wCMoYUgY:BEw84DJ3om298ECMoBgY

    Score
    9/10
    • UPX dump on OEP (original entry point)

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks