General

  • Target

    py-clash-bot-v2.0.6-win64.msi

  • Size

    80.8MB

  • Sample

    240705-ed59cavakh

  • MD5

    a3c3166576ecce249d4079a61ea29d44

  • SHA1

    ac1f230675b5e35b7f74524dc74b35b2416286db

  • SHA256

    c5fb1d847e2c8a52f3773aa55eb12cdc2ac6df983e50fefaa95cb7936f7f8ec7

  • SHA512

    0c3f529801a4db3cf70ddad592a8eee9f1841f2bc7704867331ae2b9dc0e98c7c71ccc01907c0bf051e8f8a483928ddab7ccec16ef45c13097bf119a5d6b043a

  • SSDEEP

    1572864:Gpk9lJaVpTPcYUO3opBMKXM6m8uoxiS52W6jaJkfxoa3xoqcWPbJMZ:KkYVpLctOup3m8usiSyaJkua3evY9a

Malware Config

Targets

    • Target

      py-clash-bot-v2.0.6-win64.msi

    • Size

      80.8MB

    • MD5

      a3c3166576ecce249d4079a61ea29d44

    • SHA1

      ac1f230675b5e35b7f74524dc74b35b2416286db

    • SHA256

      c5fb1d847e2c8a52f3773aa55eb12cdc2ac6df983e50fefaa95cb7936f7f8ec7

    • SHA512

      0c3f529801a4db3cf70ddad592a8eee9f1841f2bc7704867331ae2b9dc0e98c7c71ccc01907c0bf051e8f8a483928ddab7ccec16ef45c13097bf119a5d6b043a

    • SSDEEP

      1572864:Gpk9lJaVpTPcYUO3opBMKXM6m8uoxiS52W6jaJkfxoa3xoqcWPbJMZ:KkYVpLctOup3m8usiSyaJkua3evY9a

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Privilege Escalation

Event Triggered Execution

1
T1546

Installer Packages

1
T1546.016

Discovery

Query Registry

1
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

1
T1082

Tasks