General

  • Target

    Setup - Bloxshade.exe

  • Size

    9.2MB

  • Sample

    240701-f6d61axdpc

  • MD5

    dfbe896ade6ae361efd045187b9ae9f3

  • SHA1

    a5321f14809ddb9d2663685e63d4bfafb00a9f4a

  • SHA256

    4b78c95b9a8e9f7e0934cce997b176f85dcb4a662bf134bdb3ce89f3ae47288b

  • SHA512

    ff66de45f95b3782df9c3471dd7a8cc1701d9e4de5d8a991e1d7503da15d8bae8322b131b7f8fe1455678a40759b17b1ee9f011629b074dca07b588f1817faa3

  • SSDEEP

    98304:soXaczi2BKW2oqTqYhLsj4xTdhblvVXn9SXm90hSJ:soX3bqTnLsj4xbbl9X9sg0hy

Score
7/10

Malware Config

Targets

    • Target

      Setup - Bloxshade.exe

    • Size

      9.2MB

    • MD5

      dfbe896ade6ae361efd045187b9ae9f3

    • SHA1

      a5321f14809ddb9d2663685e63d4bfafb00a9f4a

    • SHA256

      4b78c95b9a8e9f7e0934cce997b176f85dcb4a662bf134bdb3ce89f3ae47288b

    • SHA512

      ff66de45f95b3782df9c3471dd7a8cc1701d9e4de5d8a991e1d7503da15d8bae8322b131b7f8fe1455678a40759b17b1ee9f011629b074dca07b588f1817faa3

    • SSDEEP

      98304:soXaczi2BKW2oqTqYhLsj4xTdhblvVXn9SXm90hSJ:soX3bqTnLsj4xbbl9X9sg0hy

    Score
    7/10
    • Executes dropped EXE

    • Loads dropped DLL

    • Checks whether UAC is enabled

    • Suspicious use of NtCreateThreadExHideFromDebugger

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Modify Registry

1
T1112

Discovery

System Information Discovery

4
T1082

Query Registry

3
T1012

Tasks