General

  • Target

    e90c642dd2df2067bc567130e0415e53a6e926870aea20d22339968f087a3d5a

  • Size

    512KB

  • Sample

    240701-epf4laygnn

  • MD5

    6d60281ce0819dc617ef6ad9dd67b379

  • SHA1

    1f21efec4256733232303f497ea6f4600bbf2b62

  • SHA256

    e90c642dd2df2067bc567130e0415e53a6e926870aea20d22339968f087a3d5a

  • SHA512

    6057491785dc08b5cf9436ff3c644b5cfbe9f86aa08b8b9d6e0f1cebccda43a7fbc52a54e983662007f0cee7b7258efc1ca4d9319d6d9b93f8bec34468f99c39

  • SSDEEP

    6144:AZXea3rdQt383PQ///NR5fKr2n0MO3LPlkUCmVs5bPQ///NR5fjlt01PB93GxK:AZwr/Ng1/Nblt01PBExK

Score
10/10

Malware Config

Targets

    • Target

      e90c642dd2df2067bc567130e0415e53a6e926870aea20d22339968f087a3d5a

    • Size

      512KB

    • MD5

      6d60281ce0819dc617ef6ad9dd67b379

    • SHA1

      1f21efec4256733232303f497ea6f4600bbf2b62

    • SHA256

      e90c642dd2df2067bc567130e0415e53a6e926870aea20d22339968f087a3d5a

    • SHA512

      6057491785dc08b5cf9436ff3c644b5cfbe9f86aa08b8b9d6e0f1cebccda43a7fbc52a54e983662007f0cee7b7258efc1ca4d9319d6d9b93f8bec34468f99c39

    • SSDEEP

      6144:AZXea3rdQt383PQ///NR5fKr2n0MO3LPlkUCmVs5bPQ///NR5fjlt01PB93GxK:AZwr/Ng1/Nblt01PBExK

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks