General

  • Target

    Mixcraft 8.1 Upgrade.exe

  • Size

    256KB

  • Sample

    250506-ynd3dstwgx

  • MD5

    b79e3b1adcd1eee12f489078ec16f278

  • SHA1

    09ab247f23c99716a258684f464f35c38ecb1175

  • SHA256

    52346c721fcb89f5fee7003bafcbd5669871b68ebe1155cc1991b3ef821d222d

  • SHA512

    82bf6af8248c39315fe1aaaab856d2068f83dc2cc3348edb315f748066fe7abd98e8476f49897bf2a84ebf71f7d3dc69d8bfe7fe469078829b8308471902e34d

  • SSDEEP

    3072:bzpzpGqrF5fedFrss26WMo/Lwg+UptOuEHBAnpK37nXR8X00rQ7gaPsro74tyJh8:rgdds1sr3F8NPaPViXFYSf

Malware Config

Extracted

Family

njrat

Version

v2.0

Botnet

HacKed

C2

yet-continental.gl.at.ply.gg:47881

Mutex

Windows

Attributes
  • reg_key

    Windows

  • splitter

    |-F-|

Targets

    • Target

      Mixcraft 8.1 Upgrade.exe

    • Size

      256KB

    • MD5

      b79e3b1adcd1eee12f489078ec16f278

    • SHA1

      09ab247f23c99716a258684f464f35c38ecb1175

    • SHA256

      52346c721fcb89f5fee7003bafcbd5669871b68ebe1155cc1991b3ef821d222d

    • SHA512

      82bf6af8248c39315fe1aaaab856d2068f83dc2cc3348edb315f748066fe7abd98e8476f49897bf2a84ebf71f7d3dc69d8bfe7fe469078829b8308471902e34d

    • SSDEEP

      3072:bzpzpGqrF5fedFrss26WMo/Lwg+UptOuEHBAnpK37nXR8X00rQ7gaPsro74tyJh8:rgdds1sr3F8NPaPViXFYSf

    • Detects DonutLoader

    • DonutLoader

      DonutLoader is a position-independent code that enables in-memory execution of VBScript, JScript, EXE, DLL files and dotNET assemblies.

    • Donutloader family

    • Njrat family

    • njRAT/Bladabindi

      Widely used RAT written in .NET.

    • Command and Scripting Interpreter: PowerShell

      Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Adds Run key to start application

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »