General

  • Target

    1ed793739b789e1ca6c3ff30c122b191524811bcbe75f22add36efc3a4bd0cb7.exe

  • Size

    40KB

  • Sample

    240702-3z4jmswglf

  • MD5

    7576314bc1dc5137f82d0f597053b7f0

  • SHA1

    7a327ad4c593a98b31d56bd82c9ef030ff34e63d

  • SHA256

    1ed793739b789e1ca6c3ff30c122b191524811bcbe75f22add36efc3a4bd0cb7

  • SHA512

    925889b1b61054336266a167ce3f20be3412e4a762d7cb3b158a86299b8df61b231c2d5683eefbe7f13e3b05284feec0c8af3ee12d90d30a0dfe63e471112ae4

  • SSDEEP

    768:eyxqjQl/EMQt4Oei7RwsHxyP7nbxzOQdJrQ4tl:JxqjQ+P04wsmJCWVr

Malware Config

Targets

    • Target

      1ed793739b789e1ca6c3ff30c122b191524811bcbe75f22add36efc3a4bd0cb7.exe

    • Size

      40KB

    • MD5

      7576314bc1dc5137f82d0f597053b7f0

    • SHA1

      7a327ad4c593a98b31d56bd82c9ef030ff34e63d

    • SHA256

      1ed793739b789e1ca6c3ff30c122b191524811bcbe75f22add36efc3a4bd0cb7

    • SHA512

      925889b1b61054336266a167ce3f20be3412e4a762d7cb3b158a86299b8df61b231c2d5683eefbe7f13e3b05284feec0c8af3ee12d90d30a0dfe63e471112ae4

    • SSDEEP

      768:eyxqjQl/EMQt4Oei7RwsHxyP7nbxzOQdJrQ4tl:JxqjQ+P04wsmJCWVr

    • Detect Neshta payload

    • Neshta

      Malware from the neshta family is designed to infect itself into other files to spread itself and cause damage.

    • Loads dropped DLL

    • Modifies system executable filetype association

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Privilege Escalation

Event Triggered Execution

1
T1546

Change Default File Association

1
T1546.001

Defense Evasion

Modify Registry

1
T1112

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks