Resubmissions

02-07-2024 05:30

240702-f7gzaayakh 10

02-07-2024 05:27

240702-f5tv3axhna 9

02-07-2024 05:22

240702-f2njwa1gnq 9

General

  • Target

    Heist Editor.exe

  • Size

    7.7MB

  • Sample

    240702-f5tv3axhna

  • MD5

    2324a543219161cd967a7c62595ab445

  • SHA1

    c5cb01869eb85be735592d20f584ce478e868624

  • SHA256

    880c660c294b6a8cecfd83182de82154b75ae2fcd723d34bd498e05771a2efb2

  • SHA512

    47a28ccb2285ef4eb4956e820049a2725c786a36bf9bec8e755ce414899e9540e8df1ebd5d715e2863fe2d447d701044391149b0edfe9b4c8b0316e0078a8173

  • SSDEEP

    196608:Su0t9MU87PZx1xYeMJhM0m7vWMBu6xi6HV5n:SuEAPZFYeMJhM0m7rPk6H7

Malware Config

Targets

    • Target

      Heist Editor.exe

    • Size

      7.7MB

    • MD5

      2324a543219161cd967a7c62595ab445

    • SHA1

      c5cb01869eb85be735592d20f584ce478e868624

    • SHA256

      880c660c294b6a8cecfd83182de82154b75ae2fcd723d34bd498e05771a2efb2

    • SHA512

      47a28ccb2285ef4eb4956e820049a2725c786a36bf9bec8e755ce414899e9540e8df1ebd5d715e2863fe2d447d701044391149b0edfe9b4c8b0316e0078a8173

    • SSDEEP

      196608:Su0t9MU87PZx1xYeMJhM0m7vWMBu6xi6HV5n:SuEAPZFYeMJhM0m7rPk6H7

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Themida packer

      Detects Themida, an advanced Windows software protection system.

    • Checks whether UAC is enabled

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

Virtualization/Sandbox Evasion

1
T1497

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

Virtualization/Sandbox Evasion

1
T1497

System Information Discovery

3
T1082

Tasks