Analysis

  • max time kernel
    149s
  • max time network
    120s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:14

General

  • Target

    d631257d449540c452514318d8f1c14c8d2d9abd0a8e2639abe803a6c4bf1fb3.exe

  • Size

    81KB

  • MD5

    a93f55a327a84853cc402a267a9572a2

  • SHA1

    09de6f59ff83a68fe6c349fc9796ce40dc06345f

  • SHA256

    d631257d449540c452514318d8f1c14c8d2d9abd0a8e2639abe803a6c4bf1fb3

  • SHA512

    22e5f5fbb7e847ee0cce695d05b3f2b67ac896e0026f11dc225cb82e9bda04b9afd65b308c86831f395db71e9d50f3cf82921b82326ed5ab8a46353c35898b67

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmhw1SqJFqJbOB:W7ZDpApYbWjIoPyPoLzV7c6Shw15+G

Score
9/10

Malware Config

Signatures

  • Renames multiple (3477) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\d631257d449540c452514318d8f1c14c8d2d9abd0a8e2639abe803a6c4bf1fb3.exe
    "C:\Users\Admin\AppData\Local\Temp\d631257d449540c452514318d8f1c14c8d2d9abd0a8e2639abe803a6c4bf1fb3.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1252

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2737914667-933161113-3798636211-1000\desktop.ini.tmp
    Filesize

    81KB

    MD5

    90d85b476bf1dc12fdfda4a1d1d39099

    SHA1

    5e88055c72305ed2f58c6ce940df325e8e703447

    SHA256

    ea3dfc428097c594cd7668539e0fab4816360851377978a126f9436941029b4b

    SHA512

    5bc468e2ac778a148d6a9ee3fb7dea5c0c16a4c8176b24969dc3943d7d633f0db84618525f285a7ec1cb6145fea229196c8a109b7bb88ccba1317edbb9160066

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    90KB

    MD5

    2edd5d791fec7a901de419e1fc086669

    SHA1

    02b92d78706b6937b935f0f4032beede033f0fd4

    SHA256

    7a1829f6c626203368fb90f690c08b15cca310208125dedcd15abf6f34116572

    SHA512

    2340f8e9beb5195ebf56a9b6f6812e218cfa1478cf9ebc3f84c1b401c9bb3dd76b24f9bba10c07f556ee5f74f813964362b1eef0f8d98ebbe6560b4b312d5200