General

  • Target

    d1f04b4bea67cbc6f469855826505a16e706b514858fa73c123df263ad34a292

  • Size

    2.4MB

  • Sample

    240704-2qbxlawcrg

  • MD5

    853f97821f33b411e011296b97d0cff3

  • SHA1

    99824a9224dd7e097cbc5804d2d9536555ef95ee

  • SHA256

    d1f04b4bea67cbc6f469855826505a16e706b514858fa73c123df263ad34a292

  • SHA512

    71bbd39e471766bcc4b4418d39ad0476cf3b894f9833be971df9b0c7a8691d51017c7f196a21844af19a0b7c5fe8f8bb05492ebf4013d05fbb29903a834e4fa2

  • SSDEEP

    49152:XN1ELQkaEIo7DFYFuIqtvcflkB78QWtyGPcBD1qouXkd/0lDb:XvELmEI8FYMcfmB7MHlkhC

Malware Config

Extracted

Family

stealc

Botnet

default

C2

http://85.28.47.4

Attributes
  • url_path

    /920475a59bac849d.php

Targets

    • Target

      d1f04b4bea67cbc6f469855826505a16e706b514858fa73c123df263ad34a292

    • Size

      2.4MB

    • MD5

      853f97821f33b411e011296b97d0cff3

    • SHA1

      99824a9224dd7e097cbc5804d2d9536555ef95ee

    • SHA256

      d1f04b4bea67cbc6f469855826505a16e706b514858fa73c123df263ad34a292

    • SHA512

      71bbd39e471766bcc4b4418d39ad0476cf3b894f9833be971df9b0c7a8691d51017c7f196a21844af19a0b7c5fe8f8bb05492ebf4013d05fbb29903a834e4fa2

    • SSDEEP

      49152:XN1ELQkaEIo7DFYFuIqtvcflkB78QWtyGPcBD1qouXkd/0lDb:XvELmEI8FYMcfmB7MHlkhC

    • Stealc

      Stealc is an infostealer written in C++.

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Discovery

Query Registry

2
T1012

System Information Discovery

1
T1082

Tasks