Analysis

  • max time kernel
    150s
  • max time network
    119s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:33

General

  • Target

    dc8abd8183866262e67d7e992a166c16deefb98c47ed4d5fe5cd4d5635744289.exe

  • Size

    90KB

  • MD5

    9b05769a342ccab3358cd868ddb920d5

  • SHA1

    33bdba45a756d53c935a801432a5c709210fa5b5

  • SHA256

    dc8abd8183866262e67d7e992a166c16deefb98c47ed4d5fe5cd4d5635744289

  • SHA512

    67736a6c0ad8048f432fe7f22a8cacf1ce47eb7ebf6a3ce908d66a6dbdc70bb26889f9c3fc707c852a0a0f7c9c2309c89659fedad36287b615d6713e878baef3

  • SSDEEP

    1536:W7ZhA7pApMaxB4b0CYJ97lEVqNR7Yge+eJG/x/OfxRfxHAu39Au3Cs:6e7WpMaxeb0CYJ97lEYNR73e+eKZOf7b

Score
9/10

Malware Config

Signatures

  • Renames multiple (2931) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\dc8abd8183866262e67d7e992a166c16deefb98c47ed4d5fe5cd4d5635744289.exe
    "C:\Users\Admin\AppData\Local\Temp\dc8abd8183866262e67d7e992a166c16deefb98c47ed4d5fe5cd4d5635744289.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1460

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1298544033-3225604241-2703760938-1000\desktop.ini.tmp
    Filesize

    90KB

    MD5

    f80c05ec68e1fa4996dfbb1fc1124d77

    SHA1

    6dc12497e522d888868146ebe8431f638096f373

    SHA256

    360c0c8b81eea691b7a3012ec659bd5bf47930fb7766330b719640cca7b415f3

    SHA512

    e37bd778ea026af8e390d3915abcebef96416b9adfb61053871e5ae09c21753aaa660c8549d717c230788e2d74ea2b598a093c573e777cfe21f7402f79400f0b

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    99KB

    MD5

    e7fb4e9dde601217e65f7a248341a2f1

    SHA1

    c5001782ad4183732b2fa094ab9448b9bc608fe3

    SHA256

    0a77454450e5d1d8986209fe6d0e834030c08fad98fa2df31e4c1f2167191090

    SHA512

    6f6a0dee3b4ec0548d4a833f56abf0be433e583b24ce588d983e083016e38662d92cf08d7af0d07434ff7a222df6e946c0f5a8b0516cc50c045c7cedfd1e96e2