General

  • Target

    e2a29285be3bda28436f30536bd8bb5141e96ddabba9beb5e63289b74419741d

  • Size

    128KB

  • Sample

    240701-ebwl5avglg

  • MD5

    7e4cca91dafab60b3daeaceb9c0cd14a

  • SHA1

    e56cc9a82bbb5b13feccd366ff09fdde829b7ec3

  • SHA256

    e2a29285be3bda28436f30536bd8bb5141e96ddabba9beb5e63289b74419741d

  • SHA512

    fa06ec34c4c8061c12ea44c117f33b1ddeb6113392d0169b03e0e4bda503e2814b195063596219f5d3b5bf1d446385f1a0f9e96c2db12efde3b77c77afa77eb9

  • SSDEEP

    3072:sfvU+klZgXnvjrow/ekNMPxMeEvPOdgujv6NLPfFFrKP9:p+kH6rkwekNMJML3OdgawrFZKP

Score
10/10

Malware Config

Targets

    • Target

      e2a29285be3bda28436f30536bd8bb5141e96ddabba9beb5e63289b74419741d

    • Size

      128KB

    • MD5

      7e4cca91dafab60b3daeaceb9c0cd14a

    • SHA1

      e56cc9a82bbb5b13feccd366ff09fdde829b7ec3

    • SHA256

      e2a29285be3bda28436f30536bd8bb5141e96ddabba9beb5e63289b74419741d

    • SHA512

      fa06ec34c4c8061c12ea44c117f33b1ddeb6113392d0169b03e0e4bda503e2814b195063596219f5d3b5bf1d446385f1a0f9e96c2db12efde3b77c77afa77eb9

    • SSDEEP

      3072:sfvU+klZgXnvjrow/ekNMPxMeEvPOdgujv6NLPfFFrKP9:p+kH6rkwekNMJML3OdgawrFZKP

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks