General

  • Target

    e6407be7788a8adbb33e5b0ecb4dc15d8245b54bbe4bf8389c832343624738b2

  • Size

    93KB

  • Sample

    240701-eh2rqawajh

  • MD5

    a901e0bc68c90f8cbb54507b291d751e

  • SHA1

    a4af4e51c57cc6d88ce5d844d821d7fb2e6e8c7e

  • SHA256

    e6407be7788a8adbb33e5b0ecb4dc15d8245b54bbe4bf8389c832343624738b2

  • SHA512

    2b6d91a600950a60d82b511b6408aadb0b3779be846cb4bda3ef5264ca9ba8d1e905f6263ea3078bc6897546674377277396b75081093effb1e66a9a39b016ab

  • SSDEEP

    1536:lAR1Lgt8LZH6sSwjkCD48AB8tZF7lSljhyg8JsRQ0RkRLJzeLD9N0iQGRNQR8Ryd:lC1L5tjkCD48bgAWe0SJdEN0s4WE+3

Score
10/10

Malware Config

Targets

    • Target

      e6407be7788a8adbb33e5b0ecb4dc15d8245b54bbe4bf8389c832343624738b2

    • Size

      93KB

    • MD5

      a901e0bc68c90f8cbb54507b291d751e

    • SHA1

      a4af4e51c57cc6d88ce5d844d821d7fb2e6e8c7e

    • SHA256

      e6407be7788a8adbb33e5b0ecb4dc15d8245b54bbe4bf8389c832343624738b2

    • SHA512

      2b6d91a600950a60d82b511b6408aadb0b3779be846cb4bda3ef5264ca9ba8d1e905f6263ea3078bc6897546674377277396b75081093effb1e66a9a39b016ab

    • SSDEEP

      1536:lAR1Lgt8LZH6sSwjkCD48AB8tZF7lSljhyg8JsRQ0RkRLJzeLD9N0iQGRNQR8Ryd:lC1L5tjkCD48bgAWe0SJdEN0s4WE+3

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks