Resubmissions

06-07-2024 13:23

240706-qmyfms1eqe 10

06-07-2024 13:05

240706-qbybha1ekb 10

General

  • Target

    pa collective agreement pay 44383.js

  • Size

    23.2MB

  • Sample

    240706-qbybha1ekb

  • MD5

    623b0a2a73dbf8de0864e244e6d2bc42

  • SHA1

    0e91209005956efb8a51376daad59898c878da76

  • SHA256

    1eb8477d6c6c18f401865d55184ff6b32bc77c239e3ca89072a53d99550a5553

  • SHA512

    1ba29b34782c7da8bd22de3ceee3f441147e9c043de3f6c27b717622a26840cee93fcc437fd699eacc49aa48899f559b80f5eddc3c4d93d48ec0234331ed906d

  • SSDEEP

    49152:j1+A08dPXWR4ba/JOtdF5pHE2lsfiaahM3o43ORV59VDKtDq1+A08dPXWR4ba/JO:Qvc43m6vc43m6vc43m6vc43m6vc43ml

Malware Config

Targets

    • Target

      pa collective agreement pay 44383.js

    • Size

      23.2MB

    • MD5

      623b0a2a73dbf8de0864e244e6d2bc42

    • SHA1

      0e91209005956efb8a51376daad59898c878da76

    • SHA256

      1eb8477d6c6c18f401865d55184ff6b32bc77c239e3ca89072a53d99550a5553

    • SHA512

      1ba29b34782c7da8bd22de3ceee3f441147e9c043de3f6c27b717622a26840cee93fcc437fd699eacc49aa48899f559b80f5eddc3c4d93d48ec0234331ed906d

    • SSDEEP

      49152:j1+A08dPXWR4ba/JOtdF5pHE2lsfiaahM3o43ORV59VDKtDq1+A08dPXWR4ba/JO:Qvc43m6vc43m6vc43m6vc43m6vc43ml

    • GootLoader

      JavaScript loader known for delivering other families such as Gootkit and Cobaltstrike.

    • Blocklisted process makes network request

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

JavaScript

1
T1059.007

Discovery

Query Registry

2
T1012

System Information Discovery

2
T1082

Tasks