General

  • Target

    e773c149ed827a590b84449a23f18bad6265ffdfd82eeab36c1248786f3a0ba4

  • Size

    190KB

  • Sample

    240701-ekxwjswanc

  • MD5

    3e4747ea7bf147fe64329ae928e2cf06

  • SHA1

    94ebd7a0b58f47dfbc9007a1104a4ec5bb1bed89

  • SHA256

    e773c149ed827a590b84449a23f18bad6265ffdfd82eeab36c1248786f3a0ba4

  • SHA512

    0c1be13bc2497381aee64ef1d317c7714bc7e78764a782dce8833af6e28f2993605ff0289c547798b48b237737eccf6cad1c2c5a7c3943ab71ae2a43782e86b6

  • SSDEEP

    1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8asUsJOVYd7n97ndJA/fqJA/fDy7Zf/FA:fnyiQSohsUsKY5Z1nyiQSohsUsKY5ZC

Score
9/10

Malware Config

Targets

    • Target

      e773c149ed827a590b84449a23f18bad6265ffdfd82eeab36c1248786f3a0ba4

    • Size

      190KB

    • MD5

      3e4747ea7bf147fe64329ae928e2cf06

    • SHA1

      94ebd7a0b58f47dfbc9007a1104a4ec5bb1bed89

    • SHA256

      e773c149ed827a590b84449a23f18bad6265ffdfd82eeab36c1248786f3a0ba4

    • SHA512

      0c1be13bc2497381aee64ef1d317c7714bc7e78764a782dce8833af6e28f2993605ff0289c547798b48b237737eccf6cad1c2c5a7c3943ab71ae2a43782e86b6

    • SSDEEP

      1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8asUsJOVYd7n97ndJA/fqJA/fDy7Zf/FA:fnyiQSohsUsKY5Z1nyiQSohsUsKY5ZC

    Score
    9/10
    • Renames multiple (2924) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks