General

  • Target

    2024-06-20_a4bbb5713ca4ae9bc316112cf79c1b48_gandcrab

  • Size

    75KB

  • MD5

    a4bbb5713ca4ae9bc316112cf79c1b48

  • SHA1

    975f0572ab518fbddc4a5217aaa249b1f249a1b0

  • SHA256

    042dfc5334e3282aa0cabaf4b8ce93412edbb257b1c7b24697e72f5443f73e95

  • SHA512

    a7c3412ed3659ff40d7c87a18564bd08afd8f0412569137a89d04c695ba748944f69bf2686ccbdae92515f4715a7922d8a993ef4097de4c7b75c1774597821a8

  • SSDEEP

    1536:y55u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5rU:IMSjOnrmBTMqqDL2/mr3IdE8we0Avu5o

Score
10/10

Malware Config

Extracted

Family

gandcrab

C2

http://gdcbghvjyqy7jclk.onion.top/

Signatures

  • Detects ransomware indicator 1 IoCs
  • GandCrab payload 1 IoCs
  • Gandcrab Payload 1 IoCs
  • Gandcrab family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 2024-06-20_a4bbb5713ca4ae9bc316112cf79c1b48_gandcrab
    .exe windows:5 windows x86 arch:x86

    40306b615af659fc1f93cfb121cc38d9


    Headers

    Imports

    Sections