General

  • Target

    2024-07-01_3ece4f31c10a92332802e57ef6c243d6_mafia

  • Size

    906KB

  • Sample

    240701-hmgh5asamj

  • MD5

    3ece4f31c10a92332802e57ef6c243d6

  • SHA1

    57993145742c950175821fcc9134375e255bf597

  • SHA256

    5bcfe8a594515c46a559d529693baa6813fe9c536794fd175462a728caa87add

  • SHA512

    2b213c73d0c46d71f7e258cef446001c94b7cb64e44dd50800593c87907d02223824afe8b75f3bec22adddc895062a76a526fe7de904f8a8d01710322a54e3a2

  • SSDEEP

    12288:iUHzKufgk0IpzpXxsPsM+80/9OCOaVLR7g1xGkgBaFSkYu8DU0OYhLu0O49gY4B:ZHVfSIpzpBsGACO0LRs1kk6i6uKVOu4B

Score
7/10

Malware Config

Targets

    • Target

      2024-07-01_3ece4f31c10a92332802e57ef6c243d6_mafia

    • Size

      906KB

    • MD5

      3ece4f31c10a92332802e57ef6c243d6

    • SHA1

      57993145742c950175821fcc9134375e255bf597

    • SHA256

      5bcfe8a594515c46a559d529693baa6813fe9c536794fd175462a728caa87add

    • SHA512

      2b213c73d0c46d71f7e258cef446001c94b7cb64e44dd50800593c87907d02223824afe8b75f3bec22adddc895062a76a526fe7de904f8a8d01710322a54e3a2

    • SSDEEP

      12288:iUHzKufgk0IpzpXxsPsM+80/9OCOaVLR7g1xGkgBaFSkYu8DU0OYhLu0O49gY4B:ZHVfSIpzpBsGACO0LRs1kk6i6uKVOu4B

    Score
    7/10
    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Writes to the Master Boot Record (MBR)

      Bootkits write to the MBR to gain persistence at a level below the operating system.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Defense Evasion

Pre-OS Boot

1
T1542

Bootkit

1
T1542.003

Discovery

Query Registry

1
T1012

System Information Discovery

2
T1082

Tasks