General
-
Target
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5
-
Size
6.0MB
-
Sample
240701-e8cwaawfpg
-
MD5
7304ef0fed52080a4cee1e43c5b2152a
-
SHA1
1688a964421a310b4114efcd96bc68d2e1476a8c
-
SHA256
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5
-
SHA512
798af86b66565f7961c35472bd1f8d5fba66b85efa43d45739e1f94dc3ffe397e2c90047709c21bc4e3d701b41641dd3a36bbdcec7a9775d0ea6ebf7d90a2c7f
-
SSDEEP
98304:FowD5bUqJPIP5Mi/HbMpGbMTFVfFlYzCiPkGtsQfvFxpm2XIKeaeopuDizw98ZbH:FoSbiP5MAHbMUi90eSZH/eopuDBj8
Behavioral task
behavioral1
Sample
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5.exe
Resource
win10v2004-20240508-en
Malware Config
Targets
-
-
Target
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5
-
Size
6.0MB
-
MD5
7304ef0fed52080a4cee1e43c5b2152a
-
SHA1
1688a964421a310b4114efcd96bc68d2e1476a8c
-
SHA256
3b7662feb1f7f52cd445b7305f95a08141c5dccd0e3e6d7c098a991b1751f9e5
-
SHA512
798af86b66565f7961c35472bd1f8d5fba66b85efa43d45739e1f94dc3ffe397e2c90047709c21bc4e3d701b41641dd3a36bbdcec7a9775d0ea6ebf7d90a2c7f
-
SSDEEP
98304:FowD5bUqJPIP5Mi/HbMpGbMTFVfFlYzCiPkGtsQfvFxpm2XIKeaeopuDizw98ZbH:FoSbiP5MAHbMUi90eSZH/eopuDBj8
Score7/10-
Loads dropped DLL
-
Writes to the Master Boot Record (MBR)
Bootkits write to the MBR to gain persistence at a level below the operating system.
-
Suspicious use of NtSetInformationThreadHideFromDebugger
-