General

  • Target

    d26c4a6679d74f04fdf43c31f98212fd2b4ade5c950dc1d86a2ab86d97141048

  • Size

    51KB

  • Sample

    240701-dkj41sthmc

  • MD5

    03adc11883396a307b9f1b58ee0834fc

  • SHA1

    561fe1d0f798f24399af6fd4ae4b5714fc45e2ab

  • SHA256

    d26c4a6679d74f04fdf43c31f98212fd2b4ade5c950dc1d86a2ab86d97141048

  • SHA512

    e454fa4d103834620cef275baaf76b50815b8e5fc9f39334ebe5b235aeb0525707288093d2e6de98d4d5e3737464cdb0fc5284209b572d59c0c83bb67591d3ca

  • SSDEEP

    768:kBT37CPKKIm0CAbLg++PJHJzIWD+dVdCYgck5sIZFlzc3/Sg2aDM9uA9DM9uAFzU:CTWn1++PJHJXA/OsIZfzc3/Q8zxi

Score
10/10

Malware Config

Targets

    • Target

      d26c4a6679d74f04fdf43c31f98212fd2b4ade5c950dc1d86a2ab86d97141048

    • Size

      51KB

    • MD5

      03adc11883396a307b9f1b58ee0834fc

    • SHA1

      561fe1d0f798f24399af6fd4ae4b5714fc45e2ab

    • SHA256

      d26c4a6679d74f04fdf43c31f98212fd2b4ade5c950dc1d86a2ab86d97141048

    • SHA512

      e454fa4d103834620cef275baaf76b50815b8e5fc9f39334ebe5b235aeb0525707288093d2e6de98d4d5e3737464cdb0fc5284209b572d59c0c83bb67591d3ca

    • SSDEEP

      768:kBT37CPKKIm0CAbLg++PJHJzIWD+dVdCYgck5sIZFlzc3/Sg2aDM9uA9DM9uAFzU:CTWn1++PJHJXA/OsIZfzc3/Q8zxi

    Score
    9/10
    • Renames multiple (197) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • UPX dump on OEP (original entry point)

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

MITRE ATT&CK Matrix

Tasks