Resubmissions

01-07-2024 10:13

240701-l829havhnd 10

01-07-2024 10:11

240701-l79xysvhkh 10

General

  • Target

    F-SecureOnlineScanner.exe

  • Size

    13.2MB

  • Sample

    240701-l829havhnd

  • MD5

    d55e98db94c13103618b16aea55c0de2

  • SHA1

    eb0dc4e5ba77b5570201d84d8e22635be0736dbe

  • SHA256

    95a893e07197a813a6d23fa5a35abcec8831197b17ea835e6fd32f2000171cf8

  • SHA512

    d64d22e4004156e6d348be8f5a1d514864e233d20547ca0893ca20bdd4c36d4ead1fc0555c6fbfe65cb0ca1f076de2735243c14d4d1c6bb90dc52b7fb74393f0

  • SSDEEP

    393216:XKWUuGCWX+wK9EI84FmdyC8rY3PzDM8IWLlYI:33Gv+wKmIHFl43XYI

Malware Config

Targets

    • Target

      F-SecureOnlineScanner.exe

    • Size

      13.2MB

    • MD5

      d55e98db94c13103618b16aea55c0de2

    • SHA1

      eb0dc4e5ba77b5570201d84d8e22635be0736dbe

    • SHA256

      95a893e07197a813a6d23fa5a35abcec8831197b17ea835e6fd32f2000171cf8

    • SHA512

      d64d22e4004156e6d348be8f5a1d514864e233d20547ca0893ca20bdd4c36d4ead1fc0555c6fbfe65cb0ca1f076de2735243c14d4d1c6bb90dc52b7fb74393f0

    • SSDEEP

      393216:XKWUuGCWX+wK9EI84FmdyC8rY3PzDM8IWLlYI:33Gv+wKmIHFl43XYI

    • RisePro

      RisePro stealer is an infostealer distributed by PrivateLoader.

    • Clears Windows event logs

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops file in System32 directory

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Event Triggered Execution

1
T1546

Netsh Helper DLL

1
T1546.007

Defense Evasion

Indicator Removal

1
T1070

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Discovery

Query Registry

5
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

4
T1082

Collection

Data from Local System

1
T1005

Tasks