General

  • Target

    eabfd8740017cffb3df820f8929c5b882c21e5db1efc5f1de3085c8cf6f5bb3b

  • Size

    96KB

  • Sample

    240701-es9kbayhnm

  • MD5

    daf09ed1e38ee92ba570a5bfa720789e

  • SHA1

    fe20001cb321759b3960a29f15ad604ec1841eac

  • SHA256

    eabfd8740017cffb3df820f8929c5b882c21e5db1efc5f1de3085c8cf6f5bb3b

  • SHA512

    9c7361061add990d59f9a848fac2f8883bd60dbd395d748a5b6d5d7492daa3c8e86c16c85da85024cdea8608c3e7deda4a8423c9b1cdd98b6a500fbadbacc6db

  • SSDEEP

    1536:h2tHcslmOq4YrpIuDCd9G1+s4X8VcdZ2JVQBKoC/CKniTCvVAva61hLDnePhVsWi:8xwOuWuD4hs4MVqZ2fQkbn1vVAva63HF

Score
10/10

Malware Config

Targets

    • Target

      eabfd8740017cffb3df820f8929c5b882c21e5db1efc5f1de3085c8cf6f5bb3b

    • Size

      96KB

    • MD5

      daf09ed1e38ee92ba570a5bfa720789e

    • SHA1

      fe20001cb321759b3960a29f15ad604ec1841eac

    • SHA256

      eabfd8740017cffb3df820f8929c5b882c21e5db1efc5f1de3085c8cf6f5bb3b

    • SHA512

      9c7361061add990d59f9a848fac2f8883bd60dbd395d748a5b6d5d7492daa3c8e86c16c85da85024cdea8608c3e7deda4a8423c9b1cdd98b6a500fbadbacc6db

    • SSDEEP

      1536:h2tHcslmOq4YrpIuDCd9G1+s4X8VcdZ2JVQBKoC/CKniTCvVAva61hLDnePhVsWi:8xwOuWuD4hs4MVqZ2fQkbn1vVAva63HF

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks