General
-
Target
2025-05-08_c32dae3ec264f2d7d53210015064e789_black-basta_elex_hijackloader_rhadamanthys_smoke-loader_tofsee
-
Size
6.9MB
-
Sample
250508-jk5cvack41
-
MD5
c32dae3ec264f2d7d53210015064e789
-
SHA1
3b80a8cc11b4f49a93bfcaaa813059bc6e8ddc16
-
SHA256
8e859e89a35d72cc2fa783903daf379cc7dcaa01f8aac2f41f6aeefaf355955d
-
SHA512
416e877685aa07ccd40581768cd4629a79a49098ae9e5c4893527de751056ed09b482e38589ff7b60f237286268f0715e9401752c047417b9f255ed9f00885f8
-
SSDEEP
49152:PabH/5uIyNabH/HJVBXdcWabH/3IyNabH/HJVBXdcaZoT3S9tsgX8zEC8ULgCSAn:YuIyatduIyatdXiTIOSAQhx0zPv
Static task
static1
Behavioral task
behavioral1
Sample
2025-05-08_c32dae3ec264f2d7d53210015064e789_black-basta_elex_hijackloader_rhadamanthys_smoke-loader_tofsee.exe
Resource
win10v2004-20250502-en
Malware Config
Targets
-
-
Target
2025-05-08_c32dae3ec264f2d7d53210015064e789_black-basta_elex_hijackloader_rhadamanthys_smoke-loader_tofsee
-
Size
6.9MB
-
MD5
c32dae3ec264f2d7d53210015064e789
-
SHA1
3b80a8cc11b4f49a93bfcaaa813059bc6e8ddc16
-
SHA256
8e859e89a35d72cc2fa783903daf379cc7dcaa01f8aac2f41f6aeefaf355955d
-
SHA512
416e877685aa07ccd40581768cd4629a79a49098ae9e5c4893527de751056ed09b482e38589ff7b60f237286268f0715e9401752c047417b9f255ed9f00885f8
-
SSDEEP
49152:PabH/5uIyNabH/HJVBXdcWabH/3IyNabH/HJVBXdcaZoT3S9tsgX8zEC8ULgCSAn:YuIyatduIyatdXiTIOSAQhx0zPv
Score10/10-
Disables service(s)
-
Grants admin privileges
Uses net.exe to modify the user's privileges.
-
Executes dropped EXE
-
Drops file in System32 directory
-
MITRE ATT&CK Enterprise v16
Persistence
Account Manipulation
1Create or Modify System Process
1Windows Service
1Privilege Escalation
Account Manipulation
1Create or Modify System Process
1Windows Service
1