General

  • Target

    ec03c8da575fa5ee4745506b340968e6.bin

  • Size

    265KB

  • Sample

    240701-el979swaqg

  • MD5

    d3f1968577c0136653300c2549a945cc

  • SHA1

    dc9653b454d10e00ab954df1e3ca7aa4c036ab81

  • SHA256

    6e9684d4b9c12a050ce73e4da9204e9b3db3cadca1ce03b8b4438dd19d36bd1d

  • SHA512

    aa79ed9de7de0d2748d77f64c48a4f8ebfe1bdc3f9a51a8e8e4c047fb7eec1ea67b8e85083159a9852335b1566baec3274865ba4c0e8f12d46fef01dc4929ff4

  • SSDEEP

    6144:9BejVcjMkq9hJZtno3ORGGpw4aBgfueyZ6hMhynnNCN/xJPAo9uqpY:beZcjMkqhJZtn0uhaBeydINCN/bN9ppY

Malware Config

Extracted

Family

nanocore

Version

1.2.2.0

C2

munan.duckdns.org:3637

munabc.duckdns.org:3637

Mutex

4d5a1bc9-ba60-4ed4-85d1-96a1836c92b0

Attributes
  • activate_away_mode

    true

  • backup_connection_host

    munabc.duckdns.org

  • backup_dns_server

    8.8.4.4

  • buffer_size

    65535

  • build_time

    2023-09-24T00:04:44.813706136Z

  • bypass_user_account_control

    true

  • bypass_user_account_control_data

  • clear_access_control

    true

  • clear_zone_identifier

    false

  • connect_delay

    4000

  • connection_port

    3637

  • default_group

    MUNA

  • enable_debug_mode

    true

  • gc_threshold

    1.048576e+07

  • keep_alive_timeout

    30000

  • keyboard_logging

    false

  • lan_timeout

    2500

  • max_packet_size

    1.048576e+07

  • mutex

    4d5a1bc9-ba60-4ed4-85d1-96a1836c92b0

  • mutex_timeout

    5000

  • prevent_system_sleep

    false

  • primary_connection_host

    munan.duckdns.org

  • primary_dns_server

    8.8.8.8

  • request_elevation

    true

  • restart_delay

    5000

  • run_delay

    0

  • run_on_startup

    true

  • set_critical_process

    true

  • timeout_interval

    5000

  • use_custom_dns_server

    false

  • version

    1.2.2.0

  • wan_timeout

    8000

Targets

    • Target

      26321ed18abb4d44668e157dcb9a123debe3b7477d95055d20e5f5d997bf60d7.exe

    • Size

      296KB

    • MD5

      ec03c8da575fa5ee4745506b340968e6

    • SHA1

      357374aa9b28d6571ebcf3b535b3cd8fe85eebba

    • SHA256

      26321ed18abb4d44668e157dcb9a123debe3b7477d95055d20e5f5d997bf60d7

    • SHA512

      2d01fa27ef375f77db7e3a896877db902ea52578aaa13aaec2aef3ce8a0199b1de56ca70602bac24f4fd2278ed5835e2c373c0626a05e95929deb93abb94137a

    • SSDEEP

      6144:ou+rdxKERB7nPpuU8Dh1tUS/fqLaiU6xVB3Y8TTp6VmSyp7jk:gdxK8B7nAU87tabNNTd6VnypU

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

System Information Discovery

1
T1082

Tasks