General

  • Target

    d04a809ec5c52c1b7beee594bed63b6f22be79c29ff2f088d0a7e5349afe38d2

  • Size

    121KB

  • Sample

    240701-dghrsatgng

  • MD5

    d939b46078a4698aaacf175df0426576

  • SHA1

    8e034489d7489ff1eb4057abcf8d1ce2bc28dc0e

  • SHA256

    d04a809ec5c52c1b7beee594bed63b6f22be79c29ff2f088d0a7e5349afe38d2

  • SHA512

    7caff26ce83833df8286d4e296419691307c535364055468f51c0d1937bd70aebca8114c842aa051fd658c89a6304e18b8b85c785c8072e023336be38f52cf24

  • SSDEEP

    1536:CTWn1++PJHJXA/OsIZfzc3/Q8Q8/8RYlaaGaa4TWn1++PJHJXA/OsIZfzc3/Q8QG:KQSoskRYpQSoskRY3

Score
9/10

Malware Config

Targets

    • Target

      d04a809ec5c52c1b7beee594bed63b6f22be79c29ff2f088d0a7e5349afe38d2

    • Size

      121KB

    • MD5

      d939b46078a4698aaacf175df0426576

    • SHA1

      8e034489d7489ff1eb4057abcf8d1ce2bc28dc0e

    • SHA256

      d04a809ec5c52c1b7beee594bed63b6f22be79c29ff2f088d0a7e5349afe38d2

    • SHA512

      7caff26ce83833df8286d4e296419691307c535364055468f51c0d1937bd70aebca8114c842aa051fd658c89a6304e18b8b85c785c8072e023336be38f52cf24

    • SSDEEP

      1536:CTWn1++PJHJXA/OsIZfzc3/Q8Q8/8RYlaaGaa4TWn1++PJHJXA/OsIZfzc3/Q8QG:KQSoskRYpQSoskRY3

    Score
    9/10
    • Renames multiple (203) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks