Analysis
-
max time kernel
24s -
max time network
119s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 03:15
Static task
static1
Behavioral task
behavioral1
Sample
d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe
Resource
win10v2004-20240508-en
General
-
Target
d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe
-
Size
80KB
-
MD5
65f1822d76b1df7ab2db4b75ec9893f0
-
SHA1
80caf95f51ff248710f6a5bdc4ec81f13c1dd363
-
SHA256
d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915
-
SHA512
a23d8f811df4c9b30e4b785f6cbeb92860f5669a728a868bd96b562dc6f3c25045ddf1704b5baf5ebbefb1b1b06bba0644b1e9a281bce128c54b5328aebca29b
-
SSDEEP
768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmh1444REXBwzEX1:W7ZDpApYbWjIoPyPoLzV7c6Sh1XSW
Malware Config
Signatures
-
Renames multiple (195) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Drops file in Program Files directory 64 IoCs
Processes:
d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exedescription ioc process File created C:\Program Files\7-Zip\Lang\ast.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\cy.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\tipresx.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\az.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-delete.avi.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ba.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\en.ttt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\kk.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\Filters\msgfilt.dll.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\7zCon.sfx.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\be.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ko.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\sa.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\uz.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-join.avi.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\bn.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ext.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\sv.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\Content.xml.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\mip.exe.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\tabskb.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\History.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\el.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ms.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\sk.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\Alphabet.xml.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\ConvertInkStore.exe.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\InkObj.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\mshwLatin.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\es.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\eu.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\hi.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ky.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\th.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\dicjp.dll.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\7-zip.dll.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\descript.ion.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ro.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\sr-spl.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\tr.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\7-zip32.dll.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\af.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\pl.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\va.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\uz-cyrl.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\IpsMigrationPlugin.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ca.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\fa.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\fi.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\mn.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ru.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\mk.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\InputPersonalization.exe.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\micaut.dll.mui.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\fr.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\gl.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\it.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Uninstall.exe.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ta.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\ku-ckb.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\nn.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\pa-in.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\si.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe File created C:\Program Files\7-Zip\Lang\sr-spc.txt.tmp d693a5af2daa7dc56f7082ea4d18efc91a63c8d40acfff03813ce5364b6de915.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-3691908287-3775019229-3534252667-1000\desktop.ini.tmpFilesize
80KB
MD5b5257aa041f4dcf85f95d9a8cd9e8d82
SHA134a2c6cd1356cf9b41265f09fa351f39b12d004d
SHA2567496287fc67e431be51dadb57f7674c391a4da294d9ed83c42ada3ecac3f0710
SHA5124ba5580c7415764d56152876f08942379de36fc4fd29a72dd11093fb20a7e6318479d520539e8f06a151d0db874f517190438012f8b356f8a63dc103873fe59d
-
C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmpFilesize
89KB
MD5247a63c44894b3b68db8b93750075289
SHA17a8315a1f1d524344d6a1ef3053052b614c8d0ed
SHA25626b0f4229957a9c2c0e746ada28c22034fd9aa6e6bf500190599a71764304775
SHA51242c1c06df09f9b54d0378c2275fa886fcebca0f65b363f81e988cd7939420d13cf749d5e9996e6189cd2a7b0cc20a7e400b854a6a31357a25c080f8b5063ed7f