General

  • Target

    29772a95fb3ed50319dc74f8be52963ee621dc151ccd94b10ea14a7123c268f7.msi

  • Size

    29.7MB

  • Sample

    240705-bhqsns1crc

  • MD5

    5421cd4bbb277efc5b163a75cac629ff

  • SHA1

    0d20c0bb978dad6bbd9065ebfc20680c241ac1e0

  • SHA256

    29772a95fb3ed50319dc74f8be52963ee621dc151ccd94b10ea14a7123c268f7

  • SHA512

    c8446d76f4ec65bc3d6a3174407f88e377c8aa260ccbed083653d114271a81a91f166a7ab45ca3d1cbdf9917f8b5aebe87364da210b9160607f2fe59a76d893c

  • SSDEEP

    786432:Ln1stHfbfy4zTE8R0BPtNg1LfjlszEJZ:GHfO4zTB8qF+zEJZ

Malware Config

Targets

    • Target

      29772a95fb3ed50319dc74f8be52963ee621dc151ccd94b10ea14a7123c268f7.msi

    • Size

      29.7MB

    • MD5

      5421cd4bbb277efc5b163a75cac629ff

    • SHA1

      0d20c0bb978dad6bbd9065ebfc20680c241ac1e0

    • SHA256

      29772a95fb3ed50319dc74f8be52963ee621dc151ccd94b10ea14a7123c268f7

    • SHA512

      c8446d76f4ec65bc3d6a3174407f88e377c8aa260ccbed083653d114271a81a91f166a7ab45ca3d1cbdf9917f8b5aebe87364da210b9160607f2fe59a76d893c

    • SSDEEP

      786432:Ln1stHfbfy4zTE8R0BPtNg1LfjlszEJZ:GHfO4zTB8qF+zEJZ

    • Creates new service(s)

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Maps connected drives based on registry

      Disk information is often read in order to detect sandboxing environments.

MITRE ATT&CK Matrix ATT&CK v13

Execution

System Services

1
T1569

Service Execution

1
T1569.002

Persistence

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Privilege Escalation

Create or Modify System Process

1
T1543

Windows Service

1
T1543.003

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

3
T1012

Peripheral Device Discovery

2
T1120

System Information Discovery

4
T1082

Tasks