General
-
Target
Virus-ast7qar.exe
-
Size
133KB
-
Sample
240701-nzfegstaqp
-
MD5
ad23e3a028bc78b343633398624cdddb
-
SHA1
d1a45e6391417289b4bc1f7bf37e10f38538a271
-
SHA256
c70c923e6611ed32f74bf3b0e2083f8defd483528e91ca8a667cdfc8eb0b2a30
-
SHA512
2d21aa9fc0ba3b0f33e65d6a8ce2827a8703e1ace688b48040f2da5e92afd85ffa87e8cd97722d559d006b744e4c56ca083dead1a75f04ba2d2b243e396f0f71
-
SSDEEP
3072:8WjMV1c/jsm1RIj9+bpsCBOgC4lOGmOl4CZUFkEC3Qy5Vj54Lzo:8QMV1Awm12Ib3OgvWOl4CZUFkECAy5VO
Behavioral task
behavioral1
Sample
Virus-ast7qar.exe
Resource
win7-20240221-en
Malware Config
Extracted
xworm
147.185.221.18:46309
-
Install_directory
%AppData%
-
install_file
PsTeam.exe
Targets
-
-
Target
Virus-ast7qar.exe
-
Size
133KB
-
MD5
ad23e3a028bc78b343633398624cdddb
-
SHA1
d1a45e6391417289b4bc1f7bf37e10f38538a271
-
SHA256
c70c923e6611ed32f74bf3b0e2083f8defd483528e91ca8a667cdfc8eb0b2a30
-
SHA512
2d21aa9fc0ba3b0f33e65d6a8ce2827a8703e1ace688b48040f2da5e92afd85ffa87e8cd97722d559d006b744e4c56ca083dead1a75f04ba2d2b243e396f0f71
-
SSDEEP
3072:8WjMV1c/jsm1RIj9+bpsCBOgC4lOGmOl4CZUFkEC3Qy5Vj54Lzo:8QMV1Awm12Ib3OgvWOl4CZUFkECAy5VO
-
Detect Xworm Payload
-
Drops startup file
-