General

  • Target

    d3dce0a70e44f0b4e4c0939e72b72a6088d7e275a84b113b85c609f95a69e715

  • Size

    203KB

  • Sample

    240701-dmwwlavaja

  • MD5

    6d7bb807f85a4f623bc48e1f1f2ab0b5

  • SHA1

    c6f83f5e9bdce01c7e1aea081d538529e023658c

  • SHA256

    d3dce0a70e44f0b4e4c0939e72b72a6088d7e275a84b113b85c609f95a69e715

  • SHA512

    34a425d5d4c741a8b9911ab30796786264bb9e6a8c6e68bda45e5ecff4f080c56786ea6d875a722822b44a21632cb7b664c39a3d7d61bb3796c8e5f9e5061abe

  • SSDEEP

    6144:RqKvb0CYJ973e+eKZOf7ftCVqKvb0CYJ973e+eKZOf7ftC7:vvbxYX7ZkCLvbxYX7ZkC7

Score
9/10

Malware Config

Targets

    • Target

      d3dce0a70e44f0b4e4c0939e72b72a6088d7e275a84b113b85c609f95a69e715

    • Size

      203KB

    • MD5

      6d7bb807f85a4f623bc48e1f1f2ab0b5

    • SHA1

      c6f83f5e9bdce01c7e1aea081d538529e023658c

    • SHA256

      d3dce0a70e44f0b4e4c0939e72b72a6088d7e275a84b113b85c609f95a69e715

    • SHA512

      34a425d5d4c741a8b9911ab30796786264bb9e6a8c6e68bda45e5ecff4f080c56786ea6d875a722822b44a21632cb7b664c39a3d7d61bb3796c8e5f9e5061abe

    • SSDEEP

      6144:RqKvb0CYJ973e+eKZOf7ftCVqKvb0CYJ973e+eKZOf7ftC7:vvbxYX7ZkCLvbxYX7ZkC7

    Score
    9/10
    • Renames multiple (122) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks