Analysis

  • max time kernel
    149s
  • max time network
    124s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:27

General

  • Target

    da63f32b0c7cc19c7076c6f3c353b11ac7846138b52a92fe512ad564a4ad63f4.exe

  • Size

    99KB

  • MD5

    ac66aaa5f96226de63c7d75f8f00c3ce

  • SHA1

    2e02ec57f5f0ccab873daea6ce9390e47f1a46ad

  • SHA256

    da63f32b0c7cc19c7076c6f3c353b11ac7846138b52a92fe512ad564a4ad63f4

  • SHA512

    2ee2c0b0ded9a1479d8ff66d260ed7fb0a22ddaa5383d9c11449f50de904d38c00d48f982540fb410c613e37fdcb472e87be25a30a05a91146dd39f84733545b

  • SSDEEP

    3072:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFslEhLfyB+:PqFF2Ie+eF1S/tUS/t4JL

Score
9/10

Malware Config

Signatures

  • Renames multiple (4617) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\da63f32b0c7cc19c7076c6f3c353b11ac7846138b52a92fe512ad564a4ad63f4.exe
    "C:\Users\Admin\AppData\Local\Temp\da63f32b0c7cc19c7076c6f3c353b11ac7846138b52a92fe512ad564a4ad63f4.exe"
    1⤵
    • Drops file in Program Files directory
    PID:316

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4204450073-1267028356-951339405-1000\desktop.ini.tmp
    Filesize

    100KB

    MD5

    ea650fd815a1eb5ae649d30eb707573c

    SHA1

    3c28602201a3ce0392bf4424692bb3adfeaeb1ff

    SHA256

    297618645296624c1d6a3371f5989ab1dff085f15bad3083bef02e78144c38c3

    SHA512

    a7c58422c436a0a60c097954962e76a2f189b63bc8e2606df9e770af007495b41c385840820529ce515e92916e02ed7f742ee3cf1c1ecfd5f16537bb1038ddbb

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    198KB

    MD5

    7003f2e9cd3a5b64d49c22667922f05a

    SHA1

    fed7a67bc0d8a2b3012538f75f66bcff02bba2ee

    SHA256

    5e98af825b30f99a41e8f654787a1b5a91820536c7e74b578999c3b8f9a4ba1e

    SHA512

    fd2aa4d215114ed434ba74bd1912c28135bd662d8d4c3323778db266c4dbb8bf94a178f4d34f1240f916aa273633e150602e67970fe2f9fe4c171f1026a3f45d