General
-
Target
a2754.Backdoor.exe
-
Size
5.0MB
-
Sample
250515-2qbltssqv6
-
MD5
5af082cdb2e8dbbdc7a0653f8537470e
-
SHA1
024d32cbf5a5ebd23b43f7f9fa1c488816a4bd4c
-
SHA256
a2754f9f14472a1dc9fcae570011f74f4a668efb9e8ab758c3b6a82970378b44
-
SHA512
ca394f7cb10a4327a321bc5cbe9d175c9fea1c75a3455a554631c15ca1e66ce81efe0af306cba958d068ba20240c245d3e0bd7f278e248ad9f7f62406b941909
-
SSDEEP
98304:x7CvLUBsgqEsTVJUI9Vvqn3N9ryhuYq//0W5CcZVsE/i:xALUCgq1zUI9EDG6X0W5Cv7
Static task
static1
Malware Config
Extracted
privateloader
http://45.133.1.107/server.txt
pastebin.com/raw/A7dSG1te
http://wfsdragon.ru/api/setStats.php
51.178.186.149
Extracted
nullmixer
http://hsiens.xyz/
Extracted
redline
media13
91.121.67.60:2151
-
auth_value
e37d5065561884bb54c8ed1baa6de446
Extracted
redline
ANI
194.104.136.5:46013
-
auth_value
9491a1c5e11eb6097e68a4fa8627fda8
Targets
-
-
Target
a2754.Backdoor.exe
-
Size
5.0MB
-
MD5
5af082cdb2e8dbbdc7a0653f8537470e
-
SHA1
024d32cbf5a5ebd23b43f7f9fa1c488816a4bd4c
-
SHA256
a2754f9f14472a1dc9fcae570011f74f4a668efb9e8ab758c3b6a82970378b44
-
SHA512
ca394f7cb10a4327a321bc5cbe9d175c9fea1c75a3455a554631c15ca1e66ce81efe0af306cba958d068ba20240c245d3e0bd7f278e248ad9f7f62406b941909
-
SSDEEP
98304:x7CvLUBsgqEsTVJUI9Vvqn3N9ryhuYq//0W5CcZVsE/i:xALUCgq1zUI9EDG6X0W5Cv7
-
Detect Fabookie payload
-
Fabookie family
-
Nullmixer family
-
PrivateLoader
PrivateLoader is a downloader sold as a pay-per-install malware distribution service.
-
Privateloader family
-
RedLine
RedLine Stealer is a malware family written in C#, first appearing in early 2020.
-
RedLine payload
-
Redline family
-
SectopRAT payload
-
Sectoprat family
-
Command and Scripting Interpreter: PowerShell
Run Powershell to modify Windows Defender settings to add exclusions for file extensions, paths, and processes.
-
Executes dropped EXE
-
Loads dropped DLL
-
Legitimate hosting services abused for malware hosting/C2
-
Looks up external IP address via web service
Uses a legitimate IP lookup service to find the infected system's external IP.
-