Analysis

  • max time kernel
    150s
  • max time network
    52s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:01

General

  • Target

    d0f972900fffe87058f0665eb8fb9b4cb4d8f7b26ec5cc79fa998fc7067a0cb2.exe

  • Size

    53KB

  • MD5

    9dd517587398fa4aa9e1c2e8421ea6de

  • SHA1

    d6461be253d1b029f54ec1afc1f9cecb0d879fed

  • SHA256

    d0f972900fffe87058f0665eb8fb9b4cb4d8f7b26ec5cc79fa998fc7067a0cb2

  • SHA512

    f87311b973386661a1f74487adf9ff8e38907364b0330c6a2ca7cad88025a041811ca31cbb9fc04df6a213db51a6e3af4a917ef2c7c859f9e2d9de94d51a8c21

  • SSDEEP

    768:/7BlpQpARFbhtF1XxXEhk8/UairBanib+UairBanibdgu:/7ZQpAp9XxXEhpUaiN+UaiNv

Score
9/10

Malware Config

Signatures

  • Renames multiple (5186) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\d0f972900fffe87058f0665eb8fb9b4cb4d8f7b26ec5cc79fa998fc7067a0cb2.exe
    "C:\Users\Admin\AppData\Local\Temp\d0f972900fffe87058f0665eb8fb9b4cb4d8f7b26ec5cc79fa998fc7067a0cb2.exe"
    1⤵
    • Drops file in Program Files directory
    PID:4580

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2539840389-1261165778-1087677076-1000\desktop.ini.tmp
    Filesize

    53KB

    MD5

    2495fe1b82c3773dc0c48b1a9d1a7675

    SHA1

    0f319d9efe68c6ecc63e4180845cadca5035d018

    SHA256

    869e0eaaf86d8b333e30ef74f1f5681dd4eee3b83b41587ddd2096b173abe330

    SHA512

    724124d78a17b3d6b9075ad8c723fde80ecae2349320f73c7a9ea93e7a0033b482727ff6499f86c936fe56914dbea76d29baa514f97c5173f9fc297947ce6fe7

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    152KB

    MD5

    c9f46a14ae184733cb30216fe24ad8d5

    SHA1

    1ba4f285f28cf553752b0d0e1ddaa32f2b24657e

    SHA256

    335f5daddb50adcba96ef11ca72b19872146b82dbb6b5b8c8916af9c959d8e3c

    SHA512

    62a5322985382a4117e1f9338547da57781f474ff15a362b064cc0a98d3da9985e17a6d90763d59f846d1525f5ac1ae415f5785dcd308c3103730c45a48d6ff6

  • memory/4580-0-0x0000000000400000-0x0000000000408000-memory.dmp
    Filesize

    32KB