General
-
Target
KnoaAgent-tasnee1-Desktop-2.msi
-
Size
2.9MB
-
Sample
250508-hdr89s1nv5
-
MD5
9fb48f2849a31de88c9a46559ca08117
-
SHA1
b3b4db4886d379e4daa2aba8a1f09c4b0070d4fd
-
SHA256
df6d409161487bb7fe79a9eb406fe3a8b6f01907bee9f5335ab3ce802597dcc4
-
SHA512
2f29c00b014b8dada6a0a3ece97c898b40b3c646e15ea809642c72978598249a0c74577acb0448c8f0fd85bbaa17102b7b89defc1cfb76b6faade00e5d588b1d
-
SSDEEP
49152:e6BNv9ua2PJzJO4NrdRifj0HNCSWCBwW10f7RgAkvd+OLEcH8lhpo8QVff5dLTtn:gP9Q4NkwtQCBwq0flgBvdvETeRVH3vtm
Static task
static1
Behavioral task
behavioral1
Sample
KnoaAgent-tasnee1-Desktop-2.msi
Resource
win10v2004-20250502-en
Behavioral task
behavioral2
Sample
KnoaAgent-tasnee1-Desktop-2.msi
Resource
win11-20250502-en
Malware Config
Targets
-
-
Target
KnoaAgent-tasnee1-Desktop-2.msi
-
Size
2.9MB
-
MD5
9fb48f2849a31de88c9a46559ca08117
-
SHA1
b3b4db4886d379e4daa2aba8a1f09c4b0070d4fd
-
SHA256
df6d409161487bb7fe79a9eb406fe3a8b6f01907bee9f5335ab3ce802597dcc4
-
SHA512
2f29c00b014b8dada6a0a3ece97c898b40b3c646e15ea809642c72978598249a0c74577acb0448c8f0fd85bbaa17102b7b89defc1cfb76b6faade00e5d588b1d
-
SSDEEP
49152:e6BNv9ua2PJzJO4NrdRifj0HNCSWCBwW10f7RgAkvd+OLEcH8lhpo8QVff5dLTtn:gP9Q4NkwtQCBwq0flgBvdvETeRVH3vtm
-
Adds policy Run key to start application
-
Modifies file permissions
-
Adds Run key to start application
-
Enumerates connected drives
Attempts to read the root path of hard drives other than the default C: drive.
-
MITRE ATT&CK Enterprise v16
Persistence
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
2Event Triggered Execution
1Installer Packages
1Privilege Escalation
Boot or Logon Autostart Execution
2Registry Run Keys / Startup Folder
2Event Triggered Execution
1Installer Packages
1Defense Evasion
File and Directory Permissions Modification
1Hide Artifacts
2Hidden Files and Directories
2Modify Registry
2System Binary Proxy Execution
1Msiexec
1