Analysis

  • max time kernel
    25s
  • max time network
    118s
  • platform
    windows7_x64
  • resource
    win7-20240419-en
  • resource tags

    arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:04

General

  • Target

    e8551374b10d13d01798da73fee37c17b49d78bf3d27ce54cb1c6ba44b2815b5.exe

  • Size

    78KB

  • MD5

    001451eab99ecbfb615c3cc965cb332b

  • SHA1

    b794456ea3e44564f2e87c4c518435ab3332f768

  • SHA256

    e8551374b10d13d01798da73fee37c17b49d78bf3d27ce54cb1c6ba44b2815b5

  • SHA512

    5f9b5ea1516cb6718bfaf411ec5818c1461dd37a14263259a2826fe1d809f11fdef4f5510f8cc2b3bf13f67d0b40fefde60f50f09541d17ec78253e69ec3ca97

  • SSDEEP

    768:W7BlpDpARFbhYQkQjjIXYvPXzWPXzK3733uF4V7en5c5HChCrmhw1SqJFqJG:W7ZDpApYbWjIoPyPoLzV7c6Shw15+G

Score
9/10

Malware Config

Signatures

  • Renames multiple (196) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\e8551374b10d13d01798da73fee37c17b49d78bf3d27ce54cb1c6ba44b2815b5.exe
    "C:\Users\Admin\AppData\Local\Temp\e8551374b10d13d01798da73fee37c17b49d78bf3d27ce54cb1c6ba44b2815b5.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2036

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-481678230-3773327859-3495911762-1000\desktop.ini.tmp
    Filesize

    79KB

    MD5

    82360cad419be27a4bb474782b0a616a

    SHA1

    870e97ff1ae1a1205ed4c5a2831874a5b12e2738

    SHA256

    1c434c7e85a0e82c0ea2e7c520417f3edd1dff3217310538fe4c50c39301a606

    SHA512

    041817e8e95c844c136c43270b472098daf08d9080444b467dadef532df5e7315cd6309ac02fed11cb38799917bb86ae8a4e5d9d938496281a4212a3f9787f77

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    88KB

    MD5

    657baf9efa0019d48b90596786184117

    SHA1

    16bcf689814edd2ba3638c081f8445a452b28d2b

    SHA256

    31ae3577bd19c3a3efeeae5467ea1a30ac0359c5cd32b763a468da862ded809d

    SHA512

    ea47d43310a46c4e1f07fd087dfdd731613ad8589d6a1b4ed9abee31e8be5ca5a82de4b9f4050c487c52da9fe0e03e44782f0b90e5bfebdd89d999dd4a383e97