General

  • Target

    2024-07-03_92951c1fbc0159842d79ccaf6edd02ad_gandcrab

  • Size

    76KB

  • Sample

    240703-st5veawbja

  • MD5

    92951c1fbc0159842d79ccaf6edd02ad

  • SHA1

    9f9c6297886d48aee0a697a831bdd2515c1ea93c

  • SHA256

    34238024d97d39872b053c362797510d19929a8aba8624b664d2463c7a23ef3c

  • SHA512

    d8605096745924359ab0f3ac8e196844bd28200b04429f510a71c26c2c764d15dbcfdc576f3b55eef0fa97763b3138a1f5293a721010f1956c646fd5fe07ebbb

  • SSDEEP

    1536:255u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5r5:8MSjOnrmBTMqqDL2/mr3IdE8we0Avu5V

Score
10/10

Malware Config

Extracted

Family

gandcrab

C2

http://gdcbghvjyqy7jclk.onion.top/

Targets

    • Target

      2024-07-03_92951c1fbc0159842d79ccaf6edd02ad_gandcrab

    • Size

      76KB

    • MD5

      92951c1fbc0159842d79ccaf6edd02ad

    • SHA1

      9f9c6297886d48aee0a697a831bdd2515c1ea93c

    • SHA256

      34238024d97d39872b053c362797510d19929a8aba8624b664d2463c7a23ef3c

    • SHA512

      d8605096745924359ab0f3ac8e196844bd28200b04429f510a71c26c2c764d15dbcfdc576f3b55eef0fa97763b3138a1f5293a721010f1956c646fd5fe07ebbb

    • SSDEEP

      1536:255u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5r5:8MSjOnrmBTMqqDL2/mr3IdE8we0Avu5V

    Score
    6/10
    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks