General

  • Target

    ec36b16b9e648082a0a2a8ac8a8a9cfb18b899fb8dc1ee03b12b63ba98a611b9

  • Size

    128KB

  • Sample

    240701-ev6lfawcpa

  • MD5

    1408aa5535fd208f228dbb3381e90a34

  • SHA1

    da6b92516af4dde123794a96d54161b055abc7cb

  • SHA256

    ec36b16b9e648082a0a2a8ac8a8a9cfb18b899fb8dc1ee03b12b63ba98a611b9

  • SHA512

    6d4d575b281e2f58de5f5a0776ef942669a24e754b2844c3da89c4f1a22ef3073379a3d0b077cb22578c5125d34ed7c8e4f0f1ccbd4dd28ab8bf49ffb3c0eafe

  • SSDEEP

    3072:ghLennfcrb50oCkIDuS/sg4XMfDd1AZoUBW3FJeRuaWNXmgu+tB:ghCnkn5ZIaEsg4cLdWZHEFJ7aWN1B

Score
10/10

Malware Config

Targets

    • Target

      ec36b16b9e648082a0a2a8ac8a8a9cfb18b899fb8dc1ee03b12b63ba98a611b9

    • Size

      128KB

    • MD5

      1408aa5535fd208f228dbb3381e90a34

    • SHA1

      da6b92516af4dde123794a96d54161b055abc7cb

    • SHA256

      ec36b16b9e648082a0a2a8ac8a8a9cfb18b899fb8dc1ee03b12b63ba98a611b9

    • SHA512

      6d4d575b281e2f58de5f5a0776ef942669a24e754b2844c3da89c4f1a22ef3073379a3d0b077cb22578c5125d34ed7c8e4f0f1ccbd4dd28ab8bf49ffb3c0eafe

    • SSDEEP

      3072:ghLennfcrb50oCkIDuS/sg4XMfDd1AZoUBW3FJeRuaWNXmgu+tB:ghCnkn5ZIaEsg4cLdWZHEFJ7aWN1B

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks