General

  • Target

    3b6977dcbf56f9ce153ea8a62cfb3c635bc1ff22350d6681ecc7a95ac75e2d13.exe

  • Size

    1.5MB

  • Sample

    240705-fhcchavhja

  • MD5

    7a9f369d4146188fb5e7d8a77f17aaf0

  • SHA1

    b4863508f380a358a029493e0e5bbbe4c1a954c1

  • SHA256

    3b6977dcbf56f9ce153ea8a62cfb3c635bc1ff22350d6681ecc7a95ac75e2d13

  • SHA512

    11a9b54fcc922ad7ec0184c0c7dd6a6af15a507dd89bc62a1faaa64b1dfa89e748ff02a9b722677ce1a97922a519d63bdf532aee3e6161825ff4ac22796eb4ce

  • SSDEEP

    49152:GezaTF8FcNkNdfE0pZ9oztFwIRxj4c5YVIJCdPyc:GemTLkNdfE0pZaM

Malware Config

Targets

    • Target

      3b6977dcbf56f9ce153ea8a62cfb3c635bc1ff22350d6681ecc7a95ac75e2d13.exe

    • Size

      1.5MB

    • MD5

      7a9f369d4146188fb5e7d8a77f17aaf0

    • SHA1

      b4863508f380a358a029493e0e5bbbe4c1a954c1

    • SHA256

      3b6977dcbf56f9ce153ea8a62cfb3c635bc1ff22350d6681ecc7a95ac75e2d13

    • SHA512

      11a9b54fcc922ad7ec0184c0c7dd6a6af15a507dd89bc62a1faaa64b1dfa89e748ff02a9b722677ce1a97922a519d63bdf532aee3e6161825ff4ac22796eb4ce

    • SSDEEP

      49152:GezaTF8FcNkNdfE0pZ9oztFwIRxj4c5YVIJCdPyc:GemTLkNdfE0pZaM

    • xmrig

      XMRig is a high performance, open source, cross platform CPU/GPU miner.

    • XMRig Miner payload

    • Executes dropped EXE

    • Loads dropped DLL

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Privilege Escalation

Event Triggered Execution

1
T1546

Accessibility Features

1
T1546.008

Tasks