588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825

Classification: Malicious

588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825 is a malicious file sample. Linked to Turla, Oilrig activity.

Detection summary

  • 0 antivirus detections (71% detection ratio)
  • 0 IDS alerts
  • 13 processes observed
  • 0 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Intrusion sets: TURLA (G0010) OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-05-05 18:22:38 2023-05-05 18:22:38
Turla Maltiverse 2023-03-03 04:26:37 2023-03-04 19:42:08 malicious-activity G0010 Turla
OilRig Maltiverse 2023-03-03 04:26:38 2023-03-04 19:41:53 malicious-activity G0049 OilRig

Tags

apt hacktool metasploit meterpreter apt34

Sample information

Filenames
588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
13312 bytes
MD5
2a8672b0fd29dc3b6f49935691b648bc
SHA-1
1ae4d51c2d258c4d9d77e5545ba05e691ddc642a
SHA-256
588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825
First indexed
2023-03-04 19:41:53
Last updated
2023-05-05 18:22:39

DNS requests

codewizard.ml microsoft.updatemeltdownkb7234.com

Process list

NameCommand line
588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825.exe
cmd.exe"cmd" /c whoami & systeminfo & ipconfig /all & arp /a & netstat -ano -p tcp
whoami.exe
systeminfo.exe
ipconfig.exeipconfig /all
ARP.EXEarp /a
NETSTAT.EXEnetstat -ano -p tcp
cmd.exe"cmd" /c whoami & systeminfo & ipconfig /all & arp /a & netstat -ano -p tcp
whoami.exe
systeminfo.exe
ipconfig.exeipconfig /all
ARP.EXEarp /a
NETSTAT.EXEnetstat -ano -p tcp