General

  • Target

    262a400b339deea5089433709ce559d23253e23d23c07595b515755114147e2f

  • Size

    158KB

  • Sample

    240701-fnygxszgln

  • MD5

    253ccac8a47b80287f651987c0c779ea

  • SHA1

    11db405849dbaa9b3759de921835df20fab35bc3

  • SHA256

    262a400b339deea5089433709ce559d23253e23d23c07595b515755114147e2f

  • SHA512

    af40e01bc3d36baf47eba1d5d6406220dfbcc52c6123dd8450e709fed3e72bed82aac6257fa7bdf7dd774f182919a5051e9712b2e7f1329defd0b159cb08385d

  • SSDEEP

    3072:ed5iO3xGNftsLz4oPNKMQgC6OFr41uIG5RaopW:ej3xGNVwlJ7OF08IQRa

Malware Config

Extracted

Family

stealc

Botnet

ZOV

C2

http://40.86.87.10

Attributes
  • url_path

    /108e010e8f91c38c.php

Targets

    • Target

      262a400b339deea5089433709ce559d23253e23d23c07595b515755114147e2f

    • Size

      158KB

    • MD5

      253ccac8a47b80287f651987c0c779ea

    • SHA1

      11db405849dbaa9b3759de921835df20fab35bc3

    • SHA256

      262a400b339deea5089433709ce559d23253e23d23c07595b515755114147e2f

    • SHA512

      af40e01bc3d36baf47eba1d5d6406220dfbcc52c6123dd8450e709fed3e72bed82aac6257fa7bdf7dd774f182919a5051e9712b2e7f1329defd0b159cb08385d

    • SSDEEP

      3072:ed5iO3xGNftsLz4oPNKMQgC6OFr41uIG5RaopW:ej3xGNVwlJ7OF08IQRa

    • Stealc

      Stealc is an infostealer written in C++.

    • Downloads MZ/PE file

    • Loads dropped DLL

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

3
T1552

Credentials In Files

3
T1552.001

Discovery

Query Registry

2
T1012

System Information Discovery

1
T1082

Collection

Data from Local System

3
T1005

Tasks