General

  • Target

    4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3

  • Size

    5.6MB

  • Sample

    250518-tgzy3avlx4

  • MD5

    db54ed9a28a1dadebfcd3e5b671cfca6

  • SHA1

    d2b398cd960ea2815b570a1a07736bf27657577a

  • SHA256

    4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3

  • SHA512

    733f1457ef81d7d7c172b77b07e5d3f3f73bfddf087ab2da0b2ae5b28f02e6612ad830c1fec3f8d9c27e6f68b3b18f7ae94cfe8730f049bd62fbd359d9ca707c

  • SSDEEP

    98304:0L8lUfsqjM+5opzoLLJ3TbwaVvrZE0I8Gsmr+qK9QRdJOFFMFaQEObL/jZYi0ex7:0LYQjM+5o9onJ5hrZEThbJMFjQEODZYe

Malware Config

Extracted

Family

cobaltstrike

C2

http://192.168.209.130:6666/kNMW

Attributes
  • user_agent

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MAAU)

Targets

    • Target

      4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3

    • Size

      5.6MB

    • MD5

      db54ed9a28a1dadebfcd3e5b671cfca6

    • SHA1

      d2b398cd960ea2815b570a1a07736bf27657577a

    • SHA256

      4b475ae2e5a07f7ab52a435719cb5fb38f2e97d14766db689d24521b4c9c70a3

    • SHA512

      733f1457ef81d7d7c172b77b07e5d3f3f73bfddf087ab2da0b2ae5b28f02e6612ad830c1fec3f8d9c27e6f68b3b18f7ae94cfe8730f049bd62fbd359d9ca707c

    • SSDEEP

      98304:0L8lUfsqjM+5opzoLLJ3TbwaVvrZE0I8Gsmr+qK9QRdJOFFMFaQEObL/jZYi0ex7:0LYQjM+5o9onJ5hrZEThbJMFjQEODZYe

    Score
    7/10
    • Loads dropped DLL

MITRE ATT&CK Matrix

Tasks

OSZAR »