General

  • Target

    e92ebd3e17088e9ecf9fa5c68013deabd37879c99a4f083b9d489e186f81ebe8

  • Size

    2.6MB

  • Sample

    240701-eqdpvswbna

  • MD5

    e42456cd503692c77a790d7d8a6edec3

  • SHA1

    af6bf64b482e44feb223baa426393b883922c098

  • SHA256

    e92ebd3e17088e9ecf9fa5c68013deabd37879c99a4f083b9d489e186f81ebe8

  • SHA512

    c9ac8dadeb8fd3b35239f873fc64e5e4090f79caa0ac48cee436fbe5c0ec520e77c311207edee284ee55e02f5b39baf6ce6e8af0304717fe4771c36b8c060f98

  • SSDEEP

    49152:sxX7665YxRVplZzSKntlGIiT+HvRdpcAHSjpjK3LBPB/bS:sxX7QnxrloE5dpUp4b

Malware Config

Targets

    • Target

      e92ebd3e17088e9ecf9fa5c68013deabd37879c99a4f083b9d489e186f81ebe8

    • Size

      2.6MB

    • MD5

      e42456cd503692c77a790d7d8a6edec3

    • SHA1

      af6bf64b482e44feb223baa426393b883922c098

    • SHA256

      e92ebd3e17088e9ecf9fa5c68013deabd37879c99a4f083b9d489e186f81ebe8

    • SHA512

      c9ac8dadeb8fd3b35239f873fc64e5e4090f79caa0ac48cee436fbe5c0ec520e77c311207edee284ee55e02f5b39baf6ce6e8af0304717fe4771c36b8c060f98

    • SSDEEP

      49152:sxX7665YxRVplZzSKntlGIiT+HvRdpcAHSjpjK3LBPB/bS:sxX7QnxrloE5dpUp4b

    • Drops startup file

    • Executes dropped EXE

    • Loads dropped DLL

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks