General

  • Target

    f42fa144980d61c6f1832c8aa8c0337a.bin

  • Size

    42.4MB

  • Sample

    240701-erba5ayhjm

  • MD5

    f42fa144980d61c6f1832c8aa8c0337a

  • SHA1

    c96f32a3e446d6ce87fafc01366cdd2c819528e7

  • SHA256

    46cb0bfebca7f8171307b390923ee779eafa2a2e8d000f7ea5e64653eadede5e

  • SHA512

    ee7f36eee7d07057e6b9e2576adef4ce6e0dba10231c877c09293ac5c5be35423c95a2c232e880c9733fff7576d4c039a257099b819d5d9d2adc5086ff44a30a

  • SSDEEP

    786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcHj:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRo

Malware Config

Targets

    • Target

      f42fa144980d61c6f1832c8aa8c0337a.bin

    • Size

      42.4MB

    • MD5

      f42fa144980d61c6f1832c8aa8c0337a

    • SHA1

      c96f32a3e446d6ce87fafc01366cdd2c819528e7

    • SHA256

      46cb0bfebca7f8171307b390923ee779eafa2a2e8d000f7ea5e64653eadede5e

    • SHA512

      ee7f36eee7d07057e6b9e2576adef4ce6e0dba10231c877c09293ac5c5be35423c95a2c232e880c9733fff7576d4c039a257099b819d5d9d2adc5086ff44a30a

    • SSDEEP

      786432:9wYnIe84d7m8/Mw5CaXv2S3IPlv5OqlICX1atGLJcez+yzqFqikJaaZRTdcHj:9wYn7dX/uyv28Id5PlIQk0qeyOq8DrRo

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Subvert Trust Controls

1
T1553

Install Root Certificate

1
T1553.004

Modify Registry

1
T1112

Discovery

Query Registry

1
T1012

Tasks