General

  • Target

    MHDDoS-2.4.2.rar

  • Size

    27.2MB

  • Sample

    250511-gq1kqsgj2t

  • MD5

    9dfe09255096b39f09dab2a1c2aae218

  • SHA1

    00fde4360f700c688d7e6b4d4613879e6b97c2cb

  • SHA256

    0c0a834f6e2c0598c2abf6c142515c3fa557983d91ef180bf1794a4a375acb4b

  • SHA512

    ebb785b83696358f1b4ff66c9a5ebeee559a11ddafce012763ad7786200eae9260362718b280fcba0eb8a598ecbca66b6055ae4c4950d9ae520c9692531802d5

  • SSDEEP

    786432:/3N9TjUIIZCMufj5ZsAzt0T6StkWwhW9FSSYlbmSrUC65x:fbTbIZCMuPzta6dxo9uzpG

Malware Config

Targets

    • Target

      MHDDoS-2.4.2.rar

    • Size

      27.2MB

    • MD5

      9dfe09255096b39f09dab2a1c2aae218

    • SHA1

      00fde4360f700c688d7e6b4d4613879e6b97c2cb

    • SHA256

      0c0a834f6e2c0598c2abf6c142515c3fa557983d91ef180bf1794a4a375acb4b

    • SHA512

      ebb785b83696358f1b4ff66c9a5ebeee559a11ddafce012763ad7786200eae9260362718b280fcba0eb8a598ecbca66b6055ae4c4950d9ae520c9692531802d5

    • SSDEEP

      786432:/3N9TjUIIZCMufj5ZsAzt0T6StkWwhW9FSSYlbmSrUC65x:fbTbIZCMuPzta6dxo9uzpG

    • Downloads MZ/PE file

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Event Triggered Execution: Component Object Model Hijacking

      Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.

    • Executes dropped EXE

    • Loads dropped DLL

    • Adds Run key to start application

    • Blocklisted process makes network request

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

MITRE ATT&CK Enterprise v16

Tasks

OSZAR »