General

  • Target

    e8401061dcfbfdad9b8989efbc7dd16f61535a7b52ec7c724d87fb3d89a567ba

  • Size

    132KB

  • Sample

    240701-em2brawbja

  • MD5

    c7043c060d3bf97749dca86da6ac6b92

  • SHA1

    e9683bce126136413dfd042d601a1d23118a9513

  • SHA256

    e8401061dcfbfdad9b8989efbc7dd16f61535a7b52ec7c724d87fb3d89a567ba

  • SHA512

    6601797c3629aa47f7299749d96d28bb431d189d3b1bb442a1b56262038d050982f4d90c9ff059d1dc9af561b0a06833d4366198e8c8915709e2506f7e11e2fa

  • SSDEEP

    1536:V7Zf/FAxTWoJJ0TW7JJQOEK/KK7Zf/FAxTWoJJ0TW7JJQOEK/KU:fny1/8ORny1/8OT

Score
10/10

Malware Config

Targets

    • Target

      e8401061dcfbfdad9b8989efbc7dd16f61535a7b52ec7c724d87fb3d89a567ba

    • Size

      132KB

    • MD5

      c7043c060d3bf97749dca86da6ac6b92

    • SHA1

      e9683bce126136413dfd042d601a1d23118a9513

    • SHA256

      e8401061dcfbfdad9b8989efbc7dd16f61535a7b52ec7c724d87fb3d89a567ba

    • SHA512

      6601797c3629aa47f7299749d96d28bb431d189d3b1bb442a1b56262038d050982f4d90c9ff059d1dc9af561b0a06833d4366198e8c8915709e2506f7e11e2fa

    • SSDEEP

      1536:V7Zf/FAxTWoJJ0TW7JJQOEK/KK7Zf/FAxTWoJJ0TW7JJQOEK/KU:fny1/8ORny1/8OT

    Score
    9/10
    • Renames multiple (4300) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • UPX dump on OEP (original entry point)

    • Executes dropped EXE

    • Loads dropped DLL

    • UPX packed file

      Detects executables packed with UPX/modified UPX open source packer.

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks