General

  • Target

    2024-06-19_cdac1064921d608ce2db682bfd25f089_gandcrab

  • Size

    73KB

  • MD5

    cdac1064921d608ce2db682bfd25f089

  • SHA1

    808e4cd09b92d1a9b795b6ce180de1be2e1af449

  • SHA256

    a15467372c4685b58ad4acd38eed7979b5835e6110e5047fb28f48cbeddff904

  • SHA512

    fb1867f7076e22b2d26e490417ca8baf29141057fc9091f4a32965c1ebd606efa82212b2a8d5073d0d4496a0374b1ad90a21d4fe497d4ed0f7c343c8f57cea01

  • SSDEEP

    1536:U55u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5rJ:GMSjOnrmBTMqqDL2/mr3IdE8we0Avu5F

Score
10/10

Malware Config

Extracted

Family

gandcrab

C2

http://gdcbghvjyqy7jclk.onion.top/

Signatures

  • Detects ransomware indicator 1 IoCs
  • GandCrab payload 1 IoCs
  • Gandcrab Payload 1 IoCs
  • Gandcrab family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2024-06-19_cdac1064921d608ce2db682bfd25f089_gandcrab
    .exe windows:5 windows x86 arch:x86

    40306b615af659fc1f93cfb121cc38d9


    Headers

    Imports

    Sections