Analysis
-
max time kernel
60s -
max time network
124s -
platform
windows7_x64 -
resource
win7-20240611-en -
resource tags
arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system -
submitted
01-07-2024 03:49
Behavioral task
behavioral1
Sample
e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe
Resource
win10v2004-20240508-en
General
-
Target
e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe
-
Size
82KB
-
MD5
cc293a239c3fc93446e85b79b977cdc9
-
SHA1
687f79c0c36c4042c245620db42cd0681df2b4dd
-
SHA256
e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43
-
SHA512
c7150439b2fef3a1a219ba445081a1368fe222f8525d60fb2eb715f9235ba874289c895f1f982a0c5b3c29dbf11f10af40a7d952a294dabac41c8848a9cef854
-
SSDEEP
1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8zxSLkby:fnyiQSo5Lf
Malware Config
Signatures
-
Renames multiple (195) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
UPX dump on OEP (original entry point) 4 IoCs
Processes:
resource yara_rule behavioral1/memory/2228-0-0x0000000000400000-0x000000000040B000-memory.dmp UPX C:\$Recycle.Bin\S-1-5-21-39690363-730359138-1046745555-1000\desktop.ini.tmp UPX C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp UPX behavioral1/memory/2228-58-0x0000000000400000-0x000000000040B000-memory.dmp UPX -
Processes:
resource yara_rule behavioral1/memory/2228-0-0x0000000000400000-0x000000000040B000-memory.dmp upx C:\$Recycle.Bin\S-1-5-21-39690363-730359138-1046745555-1000\desktop.ini.tmp upx C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp upx behavioral1/memory/2228-58-0x0000000000400000-0x000000000040B000-memory.dmp upx -
Drops file in Program Files directory 64 IoCs
Processes:
e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exedescription ioc process File created C:\Program Files\7-Zip\Lang\he.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\sl.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\uz-cyrl.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\mip.exe.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\ShapeCollector.exe.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\dicjp.bin.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\7zG.exe.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\fa.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\az.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\is.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\lv.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\mk.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\hu.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\fur.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\nb.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\pa-in.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\sa.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\License.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\bg.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\zh-cn.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\dicjp.dll.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-correct.avi.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\vi.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\en-US\FlickLearningWizard.exe.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\be.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\mn.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\eo.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\cy.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\yo.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-split.avi.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\History.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\fi.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\gu.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\id.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\kk.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ru.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\sq.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\Filters\odffilt.dll.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\descript.ion.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\tipresx.dll.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\va.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\el-GR\tipresx.dll.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\hr.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\IPSEventLogMsg.dll.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ext.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\mng2.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\nn.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\an.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ja.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ko.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ku.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\lij.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ne.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\tg.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\bg-BG\tipresx.dll.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\eu.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\ink\de-DE\InputPersonalization.exe.mui.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\tk.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\ga.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\it.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\pl.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\si.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\Common Files\Microsoft Shared\Filters\offfiltx.dll.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe File created C:\Program Files\7-Zip\Lang\cs.txt.tmp e34513dc9193f4551b8174ed9949b88a2a188524d6c2630adb059d2ef6762c43.exe
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-39690363-730359138-1046745555-1000\desktop.ini.tmpFilesize
83KB
MD57e11b2dd01a932585d95e1aea25f05af
SHA1e4a1ba7f042424eeccaa226372799db7f13e97c9
SHA25666b475674bd3d24595b91a3fe62b0904295f62aac2b3e9c0942b17f853c4994a
SHA5121919d0fb2ee308946cefdd0467d899b883d5777b59f6de134195d88b55ba5600973b2967200ea311524733d305e6988161630995671d015d4d77ceb8a56e58b0
-
C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmpFilesize
92KB
MD5d51ea12fc154207878ce691550b3e6d5
SHA1639f911e21577520d8d2cb2c44b76d615c34448a
SHA256b73e5d3e9da985e02ffe16636eb7eb48f498dbf6fb4b610bf6c04c4e94a8efae
SHA512b33eff027b4fd85dd713ee2fdee9e8d6cdcc6b22e6777eb765aa41dfb86f5b03ee748fb9ed0e5860f2e7e6494c8e602442c5edf8838a79abe22783083080b3dd
-
memory/2228-0-0x0000000000400000-0x000000000040B000-memory.dmpFilesize
44KB
-
memory/2228-58-0x0000000000400000-0x000000000040B000-memory.dmpFilesize
44KB