General

  • Target

    3707f28de07dc447919d0394c2410b100d99c71556b7067d69e5b9914e85b13f.exe

  • Size

    76KB

  • Sample

    240705-en9drascnn

  • MD5

    67b8c859e6f5efc58b124ad15aa03960

  • SHA1

    7528a61a0bcb47103fc925693c7b602b5f8e4467

  • SHA256

    3707f28de07dc447919d0394c2410b100d99c71556b7067d69e5b9914e85b13f

  • SHA512

    f0abb4259928b392d0953f17942c2b851c1098ca846c6dda14d3490a1fe437d9fd1404bc91398f753931e6c856b8c5045f08cc9d37f8aeaea275120765d38808

  • SSDEEP

    1536:YjV8y93KQpFQmPLRk7G50zy/riF12jvRyo0hQk7ZXw9DH2exq:c8y93KQjy7G55riF1cMo03Bwk

Malware Config

Targets

    • Target

      3707f28de07dc447919d0394c2410b100d99c71556b7067d69e5b9914e85b13f.exe

    • Size

      76KB

    • MD5

      67b8c859e6f5efc58b124ad15aa03960

    • SHA1

      7528a61a0bcb47103fc925693c7b602b5f8e4467

    • SHA256

      3707f28de07dc447919d0394c2410b100d99c71556b7067d69e5b9914e85b13f

    • SHA512

      f0abb4259928b392d0953f17942c2b851c1098ca846c6dda14d3490a1fe437d9fd1404bc91398f753931e6c856b8c5045f08cc9d37f8aeaea275120765d38808

    • SSDEEP

      1536:YjV8y93KQpFQmPLRk7G50zy/riF12jvRyo0hQk7ZXw9DH2exq:c8y93KQjy7G55riF1cMo03Bwk

    • Event Triggered Execution: AppInit DLLs

      Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

AppInit DLLs

1
T1546.010

Privilege Escalation

Event Triggered Execution

1
T1546

AppInit DLLs

1
T1546.010

Tasks