Overview
overview
10Static
static
10Release/Ce...IR.dll
windows7-x64
1Release/Ce...IR.dll
windows10-2004-x64
1Release/CeleryIn.dll
windows7-x64
1Release/CeleryIn.dll
windows10-2004-x64
1Release/Ce...ct.exe
windows7-x64
1Release/Ce...ct.exe
windows10-2004-x64
1Release/EvolveAPI.dll
windows7-x64
1Release/EvolveAPI.dll
windows10-2004-x64
1Release/Flux.dll
windows7-x64
1Release/Flux.dll
windows10-2004-x64
1Release/Guna.UI2.dll
windows7-x64
1Release/Guna.UI2.dll
windows10-2004-x64
1Release/Mi...re.dll
windows7-x64
1Release/Mi...re.dll
windows10-2004-x64
1Release/Mi...ms.dll
windows7-x64
1Release/Mi...ms.dll
windows10-2004-x64
1Release/Mi...pf.dll
windows7-x64
1Release/Mi...pf.dll
windows10-2004-x64
1Release/Mo...o.html
windows7-x64
1Release/Mo...o.html
windows10-2004-x64
1Release/Mo...ug.log
windows7-x64
1Release/Mo...ug.log
windows10-2004-x64
1Release/Mo...et.dll
windows7-x64
3Release/Mo...et.dll
windows10-2004-x64
3Release/Mo...ain.js
windows7-x64
3Release/Mo...ain.js
windows10-2004-x64
3Release/Mo...lua.js
windows7-x64
3Release/Mo...lua.js
windows10-2004-x64
3Release/Mo...ain.js
windows7-x64
3Release/Mo...ain.js
windows10-2004-x64
3Release/Mo....de.js
windows7-x64
3Release/Mo....de.js
windows10-2004-x64
3Analysis
-
max time kernel
118s -
max time network
124s -
platform
windows7_x64 -
resource
win7-20231129-en -
resource tags
arch:x64arch:x86image:win7-20231129-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 01:35
Behavioral task
behavioral1
Sample
Release/CeleryAPIR.dll
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
Release/CeleryAPIR.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral3
Sample
Release/CeleryIn.dll
Resource
win7-20240419-en
Behavioral task
behavioral4
Sample
Release/CeleryIn.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
Release/CeleryInject.exe
Resource
win7-20240508-en
Behavioral task
behavioral6
Sample
Release/CeleryInject.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral7
Sample
Release/EvolveAPI.dll
Resource
win7-20240508-en
Behavioral task
behavioral8
Sample
Release/EvolveAPI.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral9
Sample
Release/Flux.dll
Resource
win7-20240508-en
Behavioral task
behavioral10
Sample
Release/Flux.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
Release/Guna.UI2.dll
Resource
win7-20240611-en
Behavioral task
behavioral12
Sample
Release/Guna.UI2.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral13
Sample
Release/Microsoft.Web.WebView2.Core.dll
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
Release/Microsoft.Web.WebView2.Core.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
Release/Microsoft.Web.WebView2.WinForms.dll
Resource
win7-20240221-en
Behavioral task
behavioral16
Sample
Release/Microsoft.Web.WebView2.WinForms.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral17
Sample
Release/Microsoft.Web.WebView2.Wpf.dll
Resource
win7-20240419-en
Behavioral task
behavioral18
Sample
Release/Microsoft.Web.WebView2.Wpf.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral19
Sample
Release/Monaco/Monaco.html
Resource
win7-20240220-en
Behavioral task
behavioral20
Sample
Release/Monaco/Monaco.html
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
Release/Monaco/debug.log
Resource
win7-20231129-en
Behavioral task
behavioral22
Sample
Release/Monaco/debug.log
Resource
win10v2004-20240611-en
Behavioral task
behavioral23
Sample
Release/Monaco/vs/MonacoNet.dll
Resource
win7-20240508-en
Behavioral task
behavioral24
Sample
Release/Monaco/vs/MonacoNet.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
Release/Monaco/vs/base/worker/workerMain.js
Resource
win7-20240611-en
Behavioral task
behavioral26
Sample
Release/Monaco/vs/base/worker/workerMain.js
Resource
win10v2004-20240226-en
Behavioral task
behavioral27
Sample
Release/Monaco/vs/basic-languages/lua/lua.js
Resource
win7-20231129-en
Behavioral task
behavioral28
Sample
Release/Monaco/vs/basic-languages/lua/lua.js
Resource
win10v2004-20240508-en
Behavioral task
behavioral29
Sample
Release/Monaco/vs/editor/editor.main.js
Resource
win7-20240220-en
Behavioral task
behavioral30
Sample
Release/Monaco/vs/editor/editor.main.js
Resource
win10v2004-20240508-en
Behavioral task
behavioral31
Sample
Release/Monaco/vs/editor/editor.main.nls.de.js
Resource
win7-20240508-en
Behavioral task
behavioral32
Sample
Release/Monaco/vs/editor/editor.main.nls.de.js
Resource
win10v2004-20240508-en
General
-
Target
Release/Monaco/debug.log
-
Size
6KB
-
MD5
e60d3725d554ea6201f30c7da4ed9d6b
-
SHA1
880533e939e3f5ecbc37992d6c2159d729c8d39f
-
SHA256
165ac18afa08f97e79c82a96deb6815585de7b22fb07fbb40f8d8900e387d5cb
-
SHA512
ff0c7b9488ccf38733aa4881d9636d874c0dfad62c0b188fc5b8357ff18975770ad02cd14dd775be46e26d2e9092f88e50c59eb70ef8977ef2501e9030f4cced
-
SSDEEP
48:rRPPPM1112727TTwwwwLCCCND7ND7ND7ND7ajjjf7f7f7f7NCCCOOOOFFFmg4uuA:RicBBBCTTTAvHHHHHr
Malware Config
Signatures
-
Opens file in notepad (likely ransom note) 1 IoCs
Processes:
NOTEPAD.EXEpid process 2240 NOTEPAD.EXE