General

  • Target

    eab5da4e9dae94320697c7a096d7219593940185dca2d2b3e06e94c22d4f27a2

  • Size

    71KB

  • Sample

    240701-es5lcsyhnj

  • MD5

    72390645c2effdefc04c90a302ba8aa7

  • SHA1

    1c560b127ae7b463b5c9f1c7bb46a2732312d938

  • SHA256

    eab5da4e9dae94320697c7a096d7219593940185dca2d2b3e06e94c22d4f27a2

  • SHA512

    260e8ba9fa50a93890d1b4a50a1e8bb31b833d53a6268ff03a21c1957b088d3316eaa56620d7b14326b64b11f65fd379c40a20d423e6ea6174bbf3e7f2f5c5d9

  • SSDEEP

    1536:Tg3C1bZK2nG/XXFQ9K0ANQmqhOEv2AStuDIl7gcreMw2ORj7OlIRQaDbEyRCRRR:E3MZKqkFQMNVqhZzSss/re40fDe0Ey0q

Score
10/10

Malware Config

Targets

    • Target

      eab5da4e9dae94320697c7a096d7219593940185dca2d2b3e06e94c22d4f27a2

    • Size

      71KB

    • MD5

      72390645c2effdefc04c90a302ba8aa7

    • SHA1

      1c560b127ae7b463b5c9f1c7bb46a2732312d938

    • SHA256

      eab5da4e9dae94320697c7a096d7219593940185dca2d2b3e06e94c22d4f27a2

    • SHA512

      260e8ba9fa50a93890d1b4a50a1e8bb31b833d53a6268ff03a21c1957b088d3316eaa56620d7b14326b64b11f65fd379c40a20d423e6ea6174bbf3e7f2f5c5d9

    • SSDEEP

      1536:Tg3C1bZK2nG/XXFQ9K0ANQmqhOEv2AStuDIl7gcreMw2ORj7OlIRQaDbEyRCRRR:E3MZKqkFQMNVqhZzSss/re40fDe0Ey0q

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks