588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825
Classification: Malicious
588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825 is a malicious file sample. Linked to Turla, Oilrig activity.
Detection summary
- 0 antivirus detections (71% detection ratio)
- 0 IDS alerts
- 13 processes observed
- 0 contacted hosts
- 2 DNS requests
MITRE ATT&CK associations
Intrusion sets: TURLA (G0010) OILRIG (G0049)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2023-05-05 18:22:38 | 2023-05-05 18:22:38 | ||
| Turla | Maltiverse | 2023-03-03 04:26:37 | 2023-03-04 19:42:08 | malicious-activity | G0010 Turla |
| OilRig | Maltiverse | 2023-03-03 04:26:38 | 2023-03-04 19:41:53 | malicious-activity | G0049 OilRig |
Tags
apt hacktool metasploit meterpreter apt34Sample information
- Filenames
- 588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 13312 bytes
- MD5
2a8672b0fd29dc3b6f49935691b648bc- SHA-1
1ae4d51c2d258c4d9d77e5545ba05e691ddc642a- SHA-256
588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825- First indexed
- 2023-03-04 19:41:53
- Last updated
- 2023-05-05 18:22:39
DNS requests
Process list
| Name | Command line |
|---|---|
| 588fd8eba6e62c28a584781deefe512659f6665daeb8c85100e0bf7a472ad825.exe | |
| cmd.exe | "cmd" /c whoami & systeminfo & ipconfig /all & arp /a & netstat -ano -p tcp |
| whoami.exe | |
| systeminfo.exe | |
| ipconfig.exe | ipconfig /all |
| ARP.EXE | arp /a |
| NETSTAT.EXE | netstat -ano -p tcp |
| cmd.exe | "cmd" /c whoami & systeminfo & ipconfig /all & arp /a & netstat -ano -p tcp |
| whoami.exe | |
| systeminfo.exe | |
| ipconfig.exe | ipconfig /all |
| ARP.EXE | arp /a |
| NETSTAT.EXE | netstat -ano -p tcp |