General

  • Target

    11f32a76a3381a8997a58492007b7b30N.exe

  • Size

    31KB

  • Sample

    240706-xrzb3a1app

  • MD5

    11f32a76a3381a8997a58492007b7b30

  • SHA1

    e143b5cadbc5fe592b41da3859e59c4969c29a0e

  • SHA256

    d1e95320ffc1d17af652c3289b6aad7e5cc4b590d5e99cc0061f58f444570da7

  • SHA512

    40ff1725323a2d545f019ae38d3f7428e7d29b2f9142e4bf0baeb6a601236d71e44312041193faa81bc7a1c9a24cbccccb43b050a99ab4bc157ec04aad5616b7

  • SSDEEP

    768:JOdi7U8bmm64KgiV6suSRmg7tgUGi0i9QXOKa91T0W2hwhmrn8:J6QDbmm64Kg06suSRmytpGi0idKanT0C

Malware Config

Targets

    • Target

      11f32a76a3381a8997a58492007b7b30N.exe

    • Size

      31KB

    • MD5

      11f32a76a3381a8997a58492007b7b30

    • SHA1

      e143b5cadbc5fe592b41da3859e59c4969c29a0e

    • SHA256

      d1e95320ffc1d17af652c3289b6aad7e5cc4b590d5e99cc0061f58f444570da7

    • SHA512

      40ff1725323a2d545f019ae38d3f7428e7d29b2f9142e4bf0baeb6a601236d71e44312041193faa81bc7a1c9a24cbccccb43b050a99ab4bc157ec04aad5616b7

    • SSDEEP

      768:JOdi7U8bmm64KgiV6suSRmg7tgUGi0i9QXOKa91T0W2hwhmrn8:J6QDbmm64Kg06suSRmytpGi0idKanT0C

    • GandCrab payload

    • Gandcrab

      Gandcrab is a Trojan horse that encrypts files on a computer.

    • Adds Run key to start application

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Matrix ATT&CK v13

Persistence

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Privilege Escalation

Boot or Logon Autostart Execution

1
T1547

Registry Run Keys / Startup Folder

1
T1547.001

Defense Evasion

Modify Registry

1
T1112

Discovery

Query Registry

2
T1012

Peripheral Device Discovery

1
T1120

System Information Discovery

2
T1082

Tasks