Analysis

  • max time kernel
    150s
  • max time network
    118s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 03:26

General

  • Target

    da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe

  • Size

    56KB

  • MD5

    ce78daa749d6a75f8a204912837e3398

  • SHA1

    efa2f8a7b554ea5df8855b82cefac84520a40370

  • SHA256

    da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7

  • SHA512

    11d756a526e4bbad9f08db915f0abdf85727c50da1dde7850d9a208b123d2a5c44a1b88bc15a2b45015a071948d38277ac09a8449cf3a98faecae00da5e0d389

  • SSDEEP

    1536:W7ZppApAT9mZ/D5zf6ydyf+abMkF24kzK3jbrCkoRWNkzZ/D5zf6ydyf+abMkF2A:6pWpa9mZ/D5zf6ydyf+abMkF24kzK3jD

Score
9/10

Malware Config

Signatures

  • Renames multiple (3196) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe
    "C:\Users\Admin\AppData\Local\Temp\da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1676

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1298544033-3225604241-2703760938-1000\desktop.ini.tmp
    Filesize

    57KB

    MD5

    02e6633e6881882f0e9ca5ee5eb173c9

    SHA1

    abf4d5f4cf069c5b2a38457913db19b456cbe730

    SHA256

    2468b50f4c79655f831db7e25be6826ad61f86d4643949decfd29400f5a30b7f

    SHA512

    9ee7bb4a972b51695b1964ea7bea7170a4d573b393b845fc1411b5fec01a2d543211c6136271f439006e7877636080540323af0719bca2f62268f28fea71acb6

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    66KB

    MD5

    d82cc740fa8aa6b54e54790643c91669

    SHA1

    aa7237877bac4d76642298b8398c3904700f8a8a

    SHA256

    d0bb3735508736381ff39fbb553504ac61f60d65d0a816e008758b575799148c

    SHA512

    3ca4ae1b98788b244d375a48611dd9e11a32df44f22e614322c4b1ca5c83873cda1e3beb4b5900cdd007b2ace49daa05d87d8adde22f094feb6673602d51194c