General

  • Target

    92cca26f44c19fe855538b2bfd18c431.bin

  • Size

    4.2MB

  • Sample

    250507-bw79waej7y

  • MD5

    af55f09e8a003fd8d4ed237af99597eb

  • SHA1

    2b3e2a2882d86c3c56fe666da49f22410917b86e

  • SHA256

    956638fc93aaa8861e8020e930b807813c9a5330507ba9323f8aef142b61024a

  • SHA512

    820f63b5d65455bfa50ff753dd9fda2e0a5a32c928540a66a314b46c6fa5567b6f99fb464da024670559e3ae73f380d99d60372c2f277cd49f68c47078f08fee

  • SSDEEP

    98304:f6to7l1D1Y7VSgLGmVn5QixZKnUPOL6xEoovTDirW4BgAGKRRR1:fAoZ91Y7zGS/HKnUmexEpvTDAWOrb

Malware Config

Extracted

Family

gcleaner

C2

45.91.200.135

Targets

    • Target

      4a4cbb675bc99e47d5aa97b87581cc4eea0aa681376997e1e06fc32cd2450fa9.exe

    • Size

      4.2MB

    • MD5

      92cca26f44c19fe855538b2bfd18c431

    • SHA1

      bd59299765b0213578d2c8f881c13b4b16ed8ff4

    • SHA256

      4a4cbb675bc99e47d5aa97b87581cc4eea0aa681376997e1e06fc32cd2450fa9

    • SHA512

      614a7ffecab437e7d2f56e0b48b94520e7ef21557be259266a6c0d6ebe2c99f2a72194bed7956bc9268af516c935031883abb3e814ca7f1b96f24702a402047e

    • SSDEEP

      98304:cIIOs0sDc6Gmu7pHC728XCgxqTsZ9uNO4tdr:0p0sm57dCtTyNLdr

    • GCleaner

      GCleaner is a Pay-Per-Install malware loader first discovered in early 2019.

    • Gcleaner family

    • Identifies VirtualBox via ACPI registry values (likely anti-VM)

    • Downloads MZ/PE file

    • Checks BIOS information in registry

      BIOS information is often read in order to detect sandboxing environments.

    • Executes dropped EXE

    • Identifies Wine through registry keys

      Wine is a compatibility layer capable of running Windows applications, which can be used as sandboxing environment.

    • Suspicious use of NtSetInformationThreadHideFromDebugger

    • Suspicious use of SetThreadContext

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »