Analysis

  • max time kernel
    150s
  • max time network
    156s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240611-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 03:50

General

  • Target

    e37f495535de7be8de012dccc269e27a69451fbca99e94fcd48b42269436a9c8.exe

  • Size

    97KB

  • MD5

    cd439e890f97360ec8d6412cefd7172f

  • SHA1

    4d736b01a838cdbada1729f69dcc5912fed5dbaf

  • SHA256

    e37f495535de7be8de012dccc269e27a69451fbca99e94fcd48b42269436a9c8

  • SHA512

    a38ec96a52748c29e09180ac3fd37b558a796e5ff07a5f49f3773bb6f3907aaedadc1963eb1366c113743923f386985da2d09045083f38e0f1d872dec1e3c9fe

  • SSDEEP

    3072:6e7WpMaxeb0CYJ97lEYNR73e+eKZOf7f3:RqKvb0CYJ973e+eKZOf7f3

Score
9/10

Malware Config

Signatures

  • Renames multiple (4643) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\e37f495535de7be8de012dccc269e27a69451fbca99e94fcd48b42269436a9c8.exe
    "C:\Users\Admin\AppData\Local\Temp\e37f495535de7be8de012dccc269e27a69451fbca99e94fcd48b42269436a9c8.exe"
    1⤵
    • Drops file in Program Files directory
    PID:3912

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4204450073-1267028356-951339405-1000\desktop.ini.tmp
    Filesize

    97KB

    MD5

    4379cd775c7ac0f8d0952dbf9d6e4d3e

    SHA1

    431a6227074e6d6bea049574ffc517207338c75d

    SHA256

    923dbd06c3598d6678308a85a5941ce96b92f4753bcedd3d6c590d775c644a09

    SHA512

    bba09d4af053af9b7bac60d968368abf901de5d1a205b8b9327b563bcd865132f276dbdb8e62b522138e2c03995ee592490f9513351f67308a9a704c4c050b2e

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    196KB

    MD5

    a32e10839306de61f72434b5772d42ab

    SHA1

    74e6aa5045b8515b46d1998b79629cc7bf94e575

    SHA256

    728dd2d920ac8f3982b0e5bb34abe50eb206950c37963b03d3616d0ddf31bc78

    SHA512

    fb1d40731e1a792135ae626081ca05680bc73190dea167213ec2b571f4deaa45edaff94172e930685fc37e653353a8e720be5938457f907021d91e123443ce32