Analysis

  • max time kernel
    150s
  • max time network
    153s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:23

General

  • Target

    d8d98978ce808783fe2a9818e4e853db56acd3087479f762d82d2ac38472984e.exe

  • Size

    43KB

  • MD5

    3d9b7f5750d7c0799679c5e3c4bf9f69

  • SHA1

    9a837732b77236c83d40fdb73bf150aab7083f3b

  • SHA256

    d8d98978ce808783fe2a9818e4e853db56acd3087479f762d82d2ac38472984e

  • SHA512

    6262e91a7a5911fb1b51aa26ca148358dd84ca388d9dd7ea035fe4dad608108b6ac3994f4fefecd4d029e5cdf6e71146e9538ef602ad6f21e0219d154bacd35c

  • SSDEEP

    768:W7BlpppARFbhFANJKaJKDhZ/D5zf6ydyf+abMkF24kzK3jbrCkoRWNk+AhZ/D5zt:W7ZppApoJKaJKlZ/D5zf6ydyf+abMkFC

Score
9/10

Malware Config

Signatures

  • Renames multiple (4848) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\d8d98978ce808783fe2a9818e4e853db56acd3087479f762d82d2ac38472984e.exe
    "C:\Users\Admin\AppData\Local\Temp\d8d98978ce808783fe2a9818e4e853db56acd3087479f762d82d2ac38472984e.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1840

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.tmp
    Filesize

    44KB

    MD5

    3915f0b6d43de7993f6bcf5268e9fe30

    SHA1

    bb84e11c510bdc2dbd9a2822715c29f41091cd8d

    SHA256

    4b5b8e5fb4694000653fc03186082db5ce4d7015abb11cf4d66e75e27e22c90f

    SHA512

    79f6f92fe24c091f87ad5ebf9febb59789838ef5b41374f8373d6f09c69dfdc9902a5782e182623f90ece46e6dfc042d9ec0be20af57b5d02fd52c38364d18f3

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    142KB

    MD5

    0e0ee06c0e7493546edcd45e121b689a

    SHA1

    c40b209c35df6e73ea62c9192e26f52da077ba4b

    SHA256

    0fdc9e3fa7fa0ef17be7c48ef7655706a98b6badaebf804987b69be05d55e557

    SHA512

    c9d60c66b0bf2427ff82389721539b4df6500356784fcf9c9864b918573dc09d7f4f3980bcd80cd96682c770c1118de036c4d1cb0bf367471bb66a875dd4a46d