Analysis

  • max time kernel
    137s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240419-en
  • resource tags

    arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:40

General

  • Target

    ded9b43ec55645f8efc84d845c8b03ab7b4eb792162be9914560482414d56df4.exe

  • Size

    78KB

  • MD5

    b3c0a49182dbaf765c73a5d96e97378c

  • SHA1

    7a2151a6eff49aab999a959a3b5df38e91f68d32

  • SHA256

    ded9b43ec55645f8efc84d845c8b03ab7b4eb792162be9914560482414d56df4

  • SHA512

    410a8d36c5e22caf2fa9526cf316664a5829ac40631b9e71524bcd0b4557ec04a788987d14ec47387635a59c8ae432f9c14965daba24ddfd1698d9d2fe72d0fa

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmhw1SqJFqJ1:W7ZDpApYbWjIoPyPoLzV7c6Shw15+1

Score
9/10

Malware Config

Signatures

  • Renames multiple (3301) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\ded9b43ec55645f8efc84d845c8b03ab7b4eb792162be9914560482414d56df4.exe
    "C:\Users\Admin\AppData\Local\Temp\ded9b43ec55645f8efc84d845c8b03ab7b4eb792162be9914560482414d56df4.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1200

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-481678230-3773327859-3495911762-1000\desktop.ini.tmp
    Filesize

    79KB

    MD5

    db86576d9e64220f07d9022528984e79

    SHA1

    4c07eebb5f9222bc8edbc75a83abd65d05cc803f

    SHA256

    9bd14e58b64bbc8b1017f9f358c69a3040de129821be68a3240e3711d8c8a56a

    SHA512

    bf11015b6d07a8c14a368a8bfb4065512cc207695f01110f084baefc578710f7e365ce4410e9d068a87b3dd4c9304ae1089b862e5265dcbb209abe5e338d5aff

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    88KB

    MD5

    0799b683a738696520381808717ed034

    SHA1

    ac2fb63288aa419971a21dc9a31dadd0f0f70e0c

    SHA256

    78c6971a6cfbfaa2360683fcdf6a0574fae7e1570411efc070eb76c7cf37429b

    SHA512

    470b31d7444bca50bb6f6c11a0311d05e4003309925cea5d7df88a342758cefccfd4fd6ad2f7f1d2e28bc21ce4964024ed27ee5e2c484ff07eacc56d732bc41c