Analysis

  • max time kernel
    6s
  • max time network
    150s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 02:28

General

  • Target

    c5d01a6be7fd5c787736c8f9514d8db3c7a3b73379d8a4a7cf4410c9cdbe71cf.exe

  • Size

    58KB

  • MD5

    18993f52b2898952bf6dab9e5d20d17b

  • SHA1

    ee618ac8f4d62fdd7f80ee3b44d7483d7b150cb9

  • SHA256

    c5d01a6be7fd5c787736c8f9514d8db3c7a3b73379d8a4a7cf4410c9cdbe71cf

  • SHA512

    485397b3dc41f4276885c66cbdbcbb18828b933a70de1e32f369b53f16f896caea7d9d491fdbe36cec9337916deb6ee06e41d6de27688ddba1b8d78da5b7dc7f

  • SSDEEP

    768:W7BlpNLpARFbhblkYlkrt8PWGoPWGqMs1MsR5nd5nyQG+QGCU1:W7ZNLpApCZrt8PWGoPWGANdNykR

Score
9/10

Malware Config

Signatures

  • Renames multiple (215) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\c5d01a6be7fd5c787736c8f9514d8db3c7a3b73379d8a4a7cf4410c9cdbe71cf.exe
    "C:\Users\Admin\AppData\Local\Temp\c5d01a6be7fd5c787736c8f9514d8db3c7a3b73379d8a4a7cf4410c9cdbe71cf.exe"
    1⤵
    • Drops file in Program Files directory
    PID:412

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2804150937-2146708401-419095071-1000\desktop.ini.tmp
    Filesize

    59KB

    MD5

    d42f07ac7e2a876d834f3d03f38c5261

    SHA1

    6fda118bb58dd31e3d344d9b16c4d4a464e7c430

    SHA256

    f9253e1c6a66f42d2f4ad4f5830c97e75a2f3a9c3883b82c3c44da6524bd143f

    SHA512

    7e4ebd45a718de3e959d2ae8093e579ff2474af090a3f5bc1e4cbaf1a16bdacb8035517761db402acb1659bcb2284cbe96d6350282536d28edba16eb61a5fe1a

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    157KB

    MD5

    1aa3f3ea62b22979d05e016851b4bd7c

    SHA1

    572fafae2155e6ada2fd6660076196ce6d42049f

    SHA256

    7af9c25d8a8f1f944586886b8daa6f2ab5bb4328c685608c7adf2dea3d2832a2

    SHA512

    f129081643abaf8d762086e140ca472e53fabf1c5fe6cd01e844f1273401335181af3ee4a6f78e5f7ea9d7fd208adab936e8c3a83da4039da301ed57b98407dc