General

  • Target

    dd6f11369c7851bd5f3553e8d9516214.bin

  • Size

    214KB

  • Sample

    240701-ec89lsvgpc

  • MD5

    dd6f11369c7851bd5f3553e8d9516214

  • SHA1

    b2d9f99e12ac6d0e1adb70f883a220ae6e28752c

  • SHA256

    c897c6077d4a6dece0df7d91eaf9bc6be011c92b5261012ca0fa896600caaa30

  • SHA512

    5b0cce7f1ec91d4365e443c53e7ea173b3c1a22850734de68efb9692a484967fe5ce5cb38d15df90eef8ea3119f53ae8b536fed5e32df57fb2caa0ac73004973

  • SSDEEP

    3072:ZhpAyazIlyazTIFTZIPrsrVbmTk31LI2cu8vKLiGaiWdPHabe571Y:hZMazU8DsrVbmTC1Ltc1OiGa7dY1

Malware Config

Targets

    • Target

      dd6f11369c7851bd5f3553e8d9516214.bin

    • Size

      214KB

    • MD5

      dd6f11369c7851bd5f3553e8d9516214

    • SHA1

      b2d9f99e12ac6d0e1adb70f883a220ae6e28752c

    • SHA256

      c897c6077d4a6dece0df7d91eaf9bc6be011c92b5261012ca0fa896600caaa30

    • SHA512

      5b0cce7f1ec91d4365e443c53e7ea173b3c1a22850734de68efb9692a484967fe5ce5cb38d15df90eef8ea3119f53ae8b536fed5e32df57fb2caa0ac73004973

    • SSDEEP

      3072:ZhpAyazIlyazTIFTZIPrsrVbmTk31LI2cu8vKLiGaiWdPHabe571Y:hZMazU8DsrVbmTC1Ltc1OiGa7dY1

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks