General

  • Target

    f9ff32eb145f7111b13b460898298ab8397e661cd62054458de93e318cfdd886

  • Size

    1.8MB

  • Sample

    240704-gk34nszcpd

  • MD5

    796ce7f64abf748e4566d9f095bc2d35

  • SHA1

    e13e0c6fa49e367519566f449245f15d36a898c4

  • SHA256

    f9ff32eb145f7111b13b460898298ab8397e661cd62054458de93e318cfdd886

  • SHA512

    cf8890690bcd342e7c89d9f77ca00bed91b7eb83f7eec70d39ffba267703c452c6a6f59f5c90f0c50477d56fee6b8abf63120e29165ed4231530f0ffb09b3135

  • SSDEEP

    12288:p99Vbpgx4OuE+aCpBPY0PkI686WNUfWO6yuXzT5SPlSGN/A7W2FeDSIGVH/KIDgj:r1gg4CppEI6GGfWDkCQDbGV6eH81kE

Malware Config

Targets

    • Target

      f9ff32eb145f7111b13b460898298ab8397e661cd62054458de93e318cfdd886

    • Size

      1.8MB

    • MD5

      796ce7f64abf748e4566d9f095bc2d35

    • SHA1

      e13e0c6fa49e367519566f449245f15d36a898c4

    • SHA256

      f9ff32eb145f7111b13b460898298ab8397e661cd62054458de93e318cfdd886

    • SHA512

      cf8890690bcd342e7c89d9f77ca00bed91b7eb83f7eec70d39ffba267703c452c6a6f59f5c90f0c50477d56fee6b8abf63120e29165ed4231530f0ffb09b3135

    • SSDEEP

      12288:p99Vbpgx4OuE+aCpBPY0PkI686WNUfWO6yuXzT5SPlSGN/A7W2FeDSIGVH/KIDgj:r1gg4CppEI6GGfWDkCQDbGV6eH81kE

    • Modifies WinLogon for persistence

    • Modifies visiblity of hidden/system files in Explorer

    • WarzoneRat, AveMaria

      WarzoneRat is a native RAT developed in C++ with multiple plugins sold as a MaaS.

    • Warzone RAT payload

    • Boot or Logon Autostart Execution: Active Setup

      Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

3
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Active Setup

1
T1547.014

Privilege Escalation

Boot or Logon Autostart Execution

3
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Winlogon Helper DLL

1
T1547.004

Active Setup

1
T1547.014

Defense Evasion

Modify Registry

4
T1112

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Discovery

System Information Discovery

1
T1082

Tasks