General

  • Target

    a5c3c3b31b34223b71184902f90693b0d338498c8457c52d90519e733722461c

  • Size

    13.1MB

  • Sample

    240701-h7ng6ssejn

  • MD5

    b46be326be1ca152f8bbea0a0bd4b2d8

  • SHA1

    653067628deca045e2b0293aa3a7099700795081

  • SHA256

    a5c3c3b31b34223b71184902f90693b0d338498c8457c52d90519e733722461c

  • SHA512

    691e43287f6268f37f406f5bd0a9324cf28ef425b498ee6c2dcf755f15c0a91450743e5a571cf8eada528f09c196991caaefda4ddc37a3130737a181d2b1a583

  • SSDEEP

    196608:MxoVuGpJhisTVf8OkgNAKEmoSSdSCw7oftkU5qAnZqf4NwdPTxkVOBi09:MxDGpJhnFAgNw7WToqksf9dPlBj

Malware Config

Targets

    • Target

      a5c3c3b31b34223b71184902f90693b0d338498c8457c52d90519e733722461c

    • Size

      13.1MB

    • MD5

      b46be326be1ca152f8bbea0a0bd4b2d8

    • SHA1

      653067628deca045e2b0293aa3a7099700795081

    • SHA256

      a5c3c3b31b34223b71184902f90693b0d338498c8457c52d90519e733722461c

    • SHA512

      691e43287f6268f37f406f5bd0a9324cf28ef425b498ee6c2dcf755f15c0a91450743e5a571cf8eada528f09c196991caaefda4ddc37a3130737a181d2b1a583

    • SSDEEP

      196608:MxoVuGpJhisTVf8OkgNAKEmoSSdSCw7oftkU5qAnZqf4NwdPTxkVOBi09:MxDGpJhnFAgNw7WToqksf9dPlBj

    • Drops file in Drivers directory

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Impair Defenses: Safe Mode Boot

    • Loads dropped DLL

    • Checks whether UAC is enabled

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Impair Defenses

1
T1562

Safe Mode Boot

1
T1562.009

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

System Information Discovery

4
T1082

Tasks