General

  • Target

    238267c98ec07131f137309231d470c68d96edeb54682c3b6a308efdafe7ada2

  • Size

    651KB

  • Sample

    240701-ydcrkszbnm

  • MD5

    fe0539642d9b7e30817279a40b745823

  • SHA1

    168ef1b69fc807b118416df49d9d45be14c9bd21

  • SHA256

    238267c98ec07131f137309231d470c68d96edeb54682c3b6a308efdafe7ada2

  • SHA512

    8563a5a1d83c122ba92b4b265f2b9d55d3a7e449d7df0520a2a4884604a775f0c068a619f7760378672bfc69d8b8591929e158601ca2b49193120dcce9e825d5

  • SSDEEP

    6144:z9KOQS4B4GMSGJpFhCBB2RFKChKSTPIfVenSvuZHuesgcf90opucbUVTJRGuPImv:zsB4GO3K2KaUVenSquic0oYc+Be0fEQ5

Malware Config

Targets

    • Target

      238267c98ec07131f137309231d470c68d96edeb54682c3b6a308efdafe7ada2

    • Size

      651KB

    • MD5

      fe0539642d9b7e30817279a40b745823

    • SHA1

      168ef1b69fc807b118416df49d9d45be14c9bd21

    • SHA256

      238267c98ec07131f137309231d470c68d96edeb54682c3b6a308efdafe7ada2

    • SHA512

      8563a5a1d83c122ba92b4b265f2b9d55d3a7e449d7df0520a2a4884604a775f0c068a619f7760378672bfc69d8b8591929e158601ca2b49193120dcce9e825d5

    • SSDEEP

      6144:z9KOQS4B4GMSGJpFhCBB2RFKChKSTPIfVenSvuZHuesgcf90opucbUVTJRGuPImv:zsB4GO3K2KaUVenSquic0oYc+Be0fEQ5

    • Guloader,Cloudeye

      A shellcode based downloader first seen in 2020.

    • Lokibot

      Lokibot is a Password and CryptoCoin Wallet Stealer.

    • Command and Scripting Interpreter: PowerShell

      Run Powershell and hide display window.

    • Loads dropped DLL

    • Accesses Microsoft Outlook profiles

    • Legitimate hosting services abused for malware hosting/C2

    • Suspicious use of NtCreateThreadExHideFromDebugger

    • Suspicious use of NtSetInformationThreadHideFromDebugger

    • Suspicious use of SetThreadContext

    • Target

      $PLUGINSDIR/AdvSplash.dll

    • Size

      6KB

    • MD5

      6def2cf3daf850acdc1a3e7340a439c4

    • SHA1

      95d0d26f60cd5af697502cd5e53a54913ab188fb

    • SHA256

      3ec3cf21a99ab0533ec2c451df3b5542733f70b972089d5c321ad7ae3b87d175

    • SHA512

      16b1cf4783284d4a1282c569f5c416c713b4b339efcd4d3948bdf7da2194c597bd732d07ba9fabafcab323ba8c8da68845d4435ab9d1916b1810087ee1f5c413

    • SSDEEP

      96:bNcIcmLEjNev3O2obNnNlXUjDftqlqCstWpFwoS:yIpLSG3O9XX+qlqntWpF

    Score
    3/10
    • Target

      $PLUGINSDIR/BgImage.dll

    • Size

      7KB

    • MD5

      2bb17d45e5ad92053ce1e500408dd8a9

    • SHA1

      f5d3a7ee6e28df532e9ce33976c92ff30a5665e4

    • SHA256

      71ce676703dad028e4083e6b960b1ed89885877079d46d5021506eaa6d99db53

    • SHA512

      efdcb476b9b9b5691fe6b9cd77ecbe48d50c6683da01fd51c6b428cc262528fb3dcd295abe28718321b2307b0e032fcb599588f1eb00a93fd9e6a1f7b322b41f

    • SSDEEP

      96:8eXR0AKTIfv7QCUsthvNL85s4lk38Eb3CDfvEh8uLzqkNnLiEQjJ3KxkP:tvBfjbUA/85q3wEh8uLmsLpmP

    Score
    1/10
    • Target

      $PLUGINSDIR/UserInfo.dll

    • Size

      4KB

    • MD5

      8ef0e4eb7c89cdd2b552de746f5e2a53

    • SHA1

      820f681e7cec409a02b194a487d1c8af1038acf0

    • SHA256

      41293b9f6588e0fbdc8fcf2a9bd8e2b244cd5ff038fc13033378da337219c9dc

    • SHA512

      a68533e8a19637d0d44219549b24baba0dc4824424842f125600fda3edcafc4bb6bb340d57a00815f262d82373b440d58d6e4e5b2ceb29bb3f6bc4cbde66c3c5

    Score
    3/10
    • Target

      $PLUGINSDIR/nsExec.dll

    • Size

      6KB

    • MD5

      c129bc26a26be6f5816a03520bb37833

    • SHA1

      18100042155f948301701744b131c516bf26ddb8

    • SHA256

      d3694fa0503158194129d113fcc1c83177ff5a5f93d898ce0bcfe9ce12f06bf4

    • SHA512

      dbe79859c41e00a6e951cee889e7f0de29a712792fb531662285a2d6e384884518c7d5d983894c185b3d31d81213d2477cf4576b0114d352b759fe07a1704e63

    • SSDEEP

      96:y7GUaYNwCLuGFctpiKFlYJ8hH4RVHpwdEeY3kRlDr6dMqqyVgN738:8ygp3FcHi0xhYMR8dMqJVgN

    Score
    3/10

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Discovery

System Information Discovery

1
T1082

Collection

Email Collection

1
T1114

Command and Control

Web Service

1
T1102

Tasks