General

  • Target

    edc542fe63461771530cadd0064e29fc89ef66d64af30fbe8cc4d734f50bb677

  • Size

    272KB

  • Sample

    240701-eywweawdle

  • MD5

    3f89e22fbaf37996b3f3e331cd2b5ca1

  • SHA1

    8d0d856d3fdb203f3d052ad9c4045961763d67fd

  • SHA256

    edc542fe63461771530cadd0064e29fc89ef66d64af30fbe8cc4d734f50bb677

  • SHA512

    ce835e15ee50facc20f03bea41ecb330c38acb91c1239b71026b087c4d98f4306ba70d083b8c8a84d6f37b49a9046a53e8d52cc33928ce7191e7deb1949ccaf3

  • SSDEEP

    6144:KMwIRdoz18mkwkByvZ6Mxv5Rar3O6B9fZSLhZmzbByvZ6Mxv5R:KURM1817ByvNv54B9f01ZmHByvNv5

Score
10/10

Malware Config

Targets

    • Target

      edc542fe63461771530cadd0064e29fc89ef66d64af30fbe8cc4d734f50bb677

    • Size

      272KB

    • MD5

      3f89e22fbaf37996b3f3e331cd2b5ca1

    • SHA1

      8d0d856d3fdb203f3d052ad9c4045961763d67fd

    • SHA256

      edc542fe63461771530cadd0064e29fc89ef66d64af30fbe8cc4d734f50bb677

    • SHA512

      ce835e15ee50facc20f03bea41ecb330c38acb91c1239b71026b087c4d98f4306ba70d083b8c8a84d6f37b49a9046a53e8d52cc33928ce7191e7deb1949ccaf3

    • SSDEEP

      6144:KMwIRdoz18mkwkByvZ6Mxv5Rar3O6B9fZSLhZmzbByvZ6Mxv5R:KURM1817ByvNv54B9f01ZmHByvNv5

    Score
    10/10
    • Adds autorun key to be loaded by Explorer.exe on startup

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Tasks