General

  • Target

    e95bc297e3e0e63bb32900572f73adbf80de73f96e9a54179a185fd1ed7c7ce9

  • Size

    207KB

  • Sample

    240701-eqp3wswbnf

  • MD5

    e4b4c258068b8afb15624779dbf62b86

  • SHA1

    e6768ac80e50f79c79cad280bad59d56a7584a75

  • SHA256

    e95bc297e3e0e63bb32900572f73adbf80de73f96e9a54179a185fd1ed7c7ce9

  • SHA512

    14c3a614b945e8813bb47415453822551f6c0fd4a1401153d2498f05b85ed215d5194746e93159f2fdf612b7837022b8b29c51cc1bae3dd1e7014f5300eafae3

  • SSDEEP

    3072:x/Y0dsMVmYEA/vlCUMgCVjoSdoxx4KcWmjRrzyAyAtWgoJSWYVo2ASOvojoS:S0Vgt5WCVjj+VPj92d62ASOwj

Score
10/10

Malware Config

Targets

    • Target

      e95bc297e3e0e63bb32900572f73adbf80de73f96e9a54179a185fd1ed7c7ce9

    • Size

      207KB

    • MD5

      e4b4c258068b8afb15624779dbf62b86

    • SHA1

      e6768ac80e50f79c79cad280bad59d56a7584a75

    • SHA256

      e95bc297e3e0e63bb32900572f73adbf80de73f96e9a54179a185fd1ed7c7ce9

    • SHA512

      14c3a614b945e8813bb47415453822551f6c0fd4a1401153d2498f05b85ed215d5194746e93159f2fdf612b7837022b8b29c51cc1bae3dd1e7014f5300eafae3

    • SSDEEP

      3072:x/Y0dsMVmYEA/vlCUMgCVjoSdoxx4KcWmjRrzyAyAtWgoJSWYVo2ASOvojoS:S0Vgt5WCVjj+VPj92d62ASOwj

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks