General

  • Target

    e71d162be4770970835adb86db442b75fcc6607f37fd921b778ecfb8b2d78ef5

  • Size

    93KB

  • Sample

    240701-ej6gaswalf

  • MD5

    618fb6dcd0f72eecd6670ca482277615

  • SHA1

    bee6d911fe7934caeb432770ae00866f582bb336

  • SHA256

    e71d162be4770970835adb86db442b75fcc6607f37fd921b778ecfb8b2d78ef5

  • SHA512

    e263103531c7a7af9d58dd98ad1bdb34fbca1b8723f7351f85d40780aa8fc8af5f735bebb99835e61857039e1dc48878dd09a07379403174d3fbe34bcd608def

  • SSDEEP

    1536:sWvLFJOSwEo8d81beT8UuXEZsVmBv26rwPPPPPPPPPPPPPPXPPPPPPuzPPPPPP2Q:sKiSPXmbBV++68PPPPPPPPPPPPPPXPPr

Score
10/10

Malware Config

Targets

    • Target

      e71d162be4770970835adb86db442b75fcc6607f37fd921b778ecfb8b2d78ef5

    • Size

      93KB

    • MD5

      618fb6dcd0f72eecd6670ca482277615

    • SHA1

      bee6d911fe7934caeb432770ae00866f582bb336

    • SHA256

      e71d162be4770970835adb86db442b75fcc6607f37fd921b778ecfb8b2d78ef5

    • SHA512

      e263103531c7a7af9d58dd98ad1bdb34fbca1b8723f7351f85d40780aa8fc8af5f735bebb99835e61857039e1dc48878dd09a07379403174d3fbe34bcd608def

    • SSDEEP

      1536:sWvLFJOSwEo8d81beT8UuXEZsVmBv26rwPPPPPPPPPPPPPPXPPPPPPuzPPPPPP2Q:sKiSPXmbBV++68PPPPPPPPPPPPPPXPPr

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks