General

  • Target

    e7fd882038bd488e4efd7b8caaa49bcc.bin

  • Size

    41.9MB

  • Sample

    240701-ehl19svhrb

  • MD5

    e7fd882038bd488e4efd7b8caaa49bcc

  • SHA1

    f30f6c5daf7cf4fa260496702016e8648cac913a

  • SHA256

    5539897cb4fad82316a3053abe70ca1ec47e55d6f5a0c741d7e513e8dffeb57c

  • SHA512

    01f2c8a3eaa9aa118aacfd549c5d66d950825c6fc49629b1bf8b3cabdb347662a1459e64c775d2d36c19bc529dc657a35062d9f624c6d3a432e09fa682ad3266

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdn:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRt

Malware Config

Targets

    • Target

      e7fd882038bd488e4efd7b8caaa49bcc.bin

    • Size

      41.9MB

    • MD5

      e7fd882038bd488e4efd7b8caaa49bcc

    • SHA1

      f30f6c5daf7cf4fa260496702016e8648cac913a

    • SHA256

      5539897cb4fad82316a3053abe70ca1ec47e55d6f5a0c741d7e513e8dffeb57c

    • SHA512

      01f2c8a3eaa9aa118aacfd549c5d66d950825c6fc49629b1bf8b3cabdb347662a1459e64c775d2d36c19bc529dc657a35062d9f624c6d3a432e09fa682ad3266

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdn:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRt

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks