General

  • Target

    2024-07-02_24bcf28f8fb2c7910c3a25a8eb015312_magniber

  • Size

    9.9MB

  • Sample

    240703-aa6cqa1cnr

  • MD5

    24bcf28f8fb2c7910c3a25a8eb015312

  • SHA1

    2babbd7a3f87327219a50a553dc50e035a6e3f9a

  • SHA256

    9475d40751701e8e5cf44c54e428043d4e76a4868ccfa5924b687881eedca5f3

  • SHA512

    3b5c123d868caba1bd853dbe08425814788bc8411c780e8b9030957079be7c5d11dd15ccd4e96363587c35f3ef9fce64a1bd665b6a6bc6f9410f94c54e33d6d4

  • SSDEEP

    196608:TaetdpmxiHUbVaw5zph8qU9m/zmtseRML2l3hDHaI6HMaJTtGb/ki00Sv5TiK/nT:Gmf+iHoT5P8SzaD8lpiK/YBNENa29

Malware Config

Targets

    • Target

      2024-07-02_24bcf28f8fb2c7910c3a25a8eb015312_magniber

    • Size

      9.9MB

    • MD5

      24bcf28f8fb2c7910c3a25a8eb015312

    • SHA1

      2babbd7a3f87327219a50a553dc50e035a6e3f9a

    • SHA256

      9475d40751701e8e5cf44c54e428043d4e76a4868ccfa5924b687881eedca5f3

    • SHA512

      3b5c123d868caba1bd853dbe08425814788bc8411c780e8b9030957079be7c5d11dd15ccd4e96363587c35f3ef9fce64a1bd665b6a6bc6f9410f94c54e33d6d4

    • SSDEEP

      196608:TaetdpmxiHUbVaw5zph8qU9m/zmtseRML2l3hDHaI6HMaJTtGb/ki00Sv5TiK/nT:Gmf+iHoT5P8SzaD8lpiK/YBNENa29

    • SectopRAT

      SectopRAT is a remote access trojan first seen in November 2019.

    • SectopRAT payload

    • Drops startup file

    • Accesses cryptocurrency files/wallets, possible credential harvesting

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks