General

  • Target

    25480d0222227eba9a1ec39ec71c5bbfd19bd5ca10cbbcc116837b29bc9ffab4.exe

  • Size

    2.4MB

  • Sample

    240704-bads5svhkn

  • MD5

    ea97daf6283f4efd8d663a370df0b9d0

  • SHA1

    7775e60ce0faa1f21f91bba0f93d71c7788cabc3

  • SHA256

    25480d0222227eba9a1ec39ec71c5bbfd19bd5ca10cbbcc116837b29bc9ffab4

  • SHA512

    03e9f2445f9bc23e5c66206d623b3969f6a34c4618fcfc6b4020130c7d06c08cb8d38fdf11c440ebe0ad21fe3dec53100afb723756c9a6cc0aab9fc662fdab33

  • SSDEEP

    49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6St1lOqIucI1WA2e:BemTLkNdfE0pZrwg

Malware Config

Targets

    • Target

      25480d0222227eba9a1ec39ec71c5bbfd19bd5ca10cbbcc116837b29bc9ffab4.exe

    • Size

      2.4MB

    • MD5

      ea97daf6283f4efd8d663a370df0b9d0

    • SHA1

      7775e60ce0faa1f21f91bba0f93d71c7788cabc3

    • SHA256

      25480d0222227eba9a1ec39ec71c5bbfd19bd5ca10cbbcc116837b29bc9ffab4

    • SHA512

      03e9f2445f9bc23e5c66206d623b3969f6a34c4618fcfc6b4020130c7d06c08cb8d38fdf11c440ebe0ad21fe3dec53100afb723756c9a6cc0aab9fc662fdab33

    • SSDEEP

      49152:BezaTF8FcNkNdfE0pZ9ozt4wIC5aIwC+Agr6St1lOqIucI1WA2e:BemTLkNdfE0pZrwg

    • KPOT

      KPOT is an information stealer that steals user data and account credentials.

    • KPOT Core Executable

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks