Resubmissions

15/04/2025, 20:14

250415-yz8q5szqw5 8

08/03/2025, 02:02

250308-cf99zazxht 8

General

  • Target

    1.exe

  • Size

    32.8MB

  • Sample

    250308-cf99zazxht

  • MD5

    c62c1a1a3c66fb83390ece675ab76dd2

  • SHA1

    55b939abe9f03345c71f54ebe9a5f206bb64bc49

  • SHA256

    de6ed44d21e5bc9bc5c1c51f33760a5d96378308d02c2c81ef2d75e7a201fb63

  • SHA512

    b927f3bb27ae617c3a9e38bb2fecd1fc108cfa306408da657973a1e8ab3158a09b00285987acd0ef8ec14d2074d3bf485effd114ca3850ac820e01838e6a19c6

  • SSDEEP

    786432:+Fxb8yuOgT5S+u6wrqImbWtVd5l5jMvti0Jz8+aZ8J9HZhkS3gXbwHPc:+Fxb8yuOgtO6oqIXtVd5l5jMvssz8T0G

Score
8/10

Malware Config

Targets

    • Target

      1.exe

    • Size

      32.8MB

    • MD5

      c62c1a1a3c66fb83390ece675ab76dd2

    • SHA1

      55b939abe9f03345c71f54ebe9a5f206bb64bc49

    • SHA256

      de6ed44d21e5bc9bc5c1c51f33760a5d96378308d02c2c81ef2d75e7a201fb63

    • SHA512

      b927f3bb27ae617c3a9e38bb2fecd1fc108cfa306408da657973a1e8ab3158a09b00285987acd0ef8ec14d2074d3bf485effd114ca3850ac820e01838e6a19c6

    • SSDEEP

      786432:+Fxb8yuOgT5S+u6wrqImbWtVd5l5jMvti0Jz8+aZ8J9HZhkS3gXbwHPc:+Fxb8yuOgtO6oqIXtVd5l5jMvssz8T0G

    Score
    8/10
    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Blocklisted process makes network request

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Drops file in System32 directory

MITRE ATT&CK Enterprise v15

Tasks

OSZAR »