General
-
Target
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3
-
Size
5.6MB
-
Sample
250518-tgzy3avlx4
-
MD5
db54ed9a28a1dadebfcd3e5b671cfca6
-
SHA1
d2b398cd960ea2815b570a1a07736bf27657577a
-
SHA256
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3
-
SHA512
733f1457ef81d7d7c172b77b07e5d3f3f73bfddf087ab2da0b2ae5b28f02e6612ad830c1fec3f8d9c27e6f68b3b18f7ae94cfe8730f049bd62fbd359d9ca707c
-
SSDEEP
98304:0L8lUfsqjM+5opzoLLJ3TbwaVvrZE0I8Gsmr+qK9QRdJOFFMFaQEObL/jZYi0ex7:0LYQjM+5o9onJ5hrZEThbJMFjQEODZYe
Behavioral task
behavioral1
Sample
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3.exe
Resource
win10v2004-20250502-en
Behavioral task
behavioral2
Sample
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3.exe
Resource
win11-20250502-en
Malware Config
Extracted
cobaltstrike
http://192.168.209.130:6666/kNMW
-
user_agent
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MAAU)
Targets
-
-
Target
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3
-
Size
5.6MB
-
MD5
db54ed9a28a1dadebfcd3e5b671cfca6
-
SHA1
d2b398cd960ea2815b570a1a07736bf27657577a
-
SHA256
4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3
-
SHA512
733f1457ef81d7d7c172b77b07e5d3f3f73bfddf087ab2da0b2ae5b28f02e6612ad830c1fec3f8d9c27e6f68b3b18f7ae94cfe8730f049bd62fbd359d9ca707c
-
SSDEEP
98304:0L8lUfsqjM+5opzoLLJ3TbwaVvrZE0I8Gsmr+qK9QRdJOFFMFaQEObL/jZYi0ex7:0LYQjM+5o9onJ5hrZEThbJMFjQEODZYe
Score7/10-
Loads dropped DLL
-