Analysis

  • max time kernel
    150s
  • max time network
    155s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:26

General

  • Target

    da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe

  • Size

    56KB

  • MD5

    ce78daa749d6a75f8a204912837e3398

  • SHA1

    efa2f8a7b554ea5df8855b82cefac84520a40370

  • SHA256

    da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7

  • SHA512

    11d756a526e4bbad9f08db915f0abdf85727c50da1dde7850d9a208b123d2a5c44a1b88bc15a2b45015a071948d38277ac09a8449cf3a98faecae00da5e0d389

  • SSDEEP

    1536:W7ZppApAT9mZ/D5zf6ydyf+abMkF24kzK3jbrCkoRWNkzZ/D5zf6ydyf+abMkF2A:6pWpa9mZ/D5zf6ydyf+abMkF24kzK3jD

Score
9/10

Malware Config

Signatures

  • Renames multiple (4693) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe
    "C:\Users\Admin\AppData\Local\Temp\da59d427cb5838518c5313973ca19c2b49199c7153c80854b742de801e40b6c7.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2800

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2080292272-204036150-2159171770-1000\desktop.ini.tmp
    Filesize

    57KB

    MD5

    f20193e37dd163157207467f27890292

    SHA1

    9729f39aee333ff1d4caae9e69ddbc6187c3ee36

    SHA256

    626863b3f47324c1c5414945d83f1a8c45cac3c5eac112f2cb354691ff480c29

    SHA512

    c64d0677f5e761837564885d8e64f2e2ecca2deac9612373234cf7627755c9331dd2d93060d6704d22a5eec89aba2c57686b59405b91b4c4c495ce4cca87a799

  • C:\Program Files\7-Zip\7-zip.dll.exe
    Filesize

    155KB

    MD5

    5911229c5ca470021c26d0e154bb6753

    SHA1

    a2f69e59935ceaf404f072ebaaf5112033c4e2d6

    SHA256

    3b5c3be7c9c43d75429468896977ef69f37d2ba826c42d86b8a44ea87a5a38d1

    SHA512

    595f88f180de0d1ada02bab89a75a79a4d19ac62bc3ec846fe95f7dd50c2b87ab8bd7414d2f468356e358a8e25ceb4506c884db778c3421930e971d4eedd6840