General

  • Target

    e4eef23f5ce6a821b6e06043914e5829977bc15d721d5e502c5f05bde617dbb3

  • Size

    256KB

  • Sample

    240701-ef8ggsyepk

  • MD5

    ba63418c45277992fec1d0dfed1110f9

  • SHA1

    4d036b8eb736cf2c9df680a7d783c07900e614f3

  • SHA256

    e4eef23f5ce6a821b6e06043914e5829977bc15d721d5e502c5f05bde617dbb3

  • SHA512

    b925e78cdca44def4e7e160a317b291e1645b6188618b192feed32614380ef8fe22290c327ead67ebd0c1811fc37aefdecc97f85ffc2d8f1dc44b5b1c1fa96d4

  • SSDEEP

    6144:IcKQxcst89C81NByvZ6Mxv5Rar3O6B9fZSLhZmzbBy9:ITQxW9C8HByvNv54B9f01ZmHBy9

Score
10/10

Malware Config

Targets

    • Target

      e4eef23f5ce6a821b6e06043914e5829977bc15d721d5e502c5f05bde617dbb3

    • Size

      256KB

    • MD5

      ba63418c45277992fec1d0dfed1110f9

    • SHA1

      4d036b8eb736cf2c9df680a7d783c07900e614f3

    • SHA256

      e4eef23f5ce6a821b6e06043914e5829977bc15d721d5e502c5f05bde617dbb3

    • SHA512

      b925e78cdca44def4e7e160a317b291e1645b6188618b192feed32614380ef8fe22290c327ead67ebd0c1811fc37aefdecc97f85ffc2d8f1dc44b5b1c1fa96d4

    • SSDEEP

      6144:IcKQxcst89C81NByvZ6Mxv5Rar3O6B9fZSLhZmzbBy9:ITQxW9C8HByvNv54B9f01ZmHBy9

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks