Analysis

  • max time kernel
    150s
  • max time network
    124s
  • platform
    windows7_x64
  • resource
    win7-20240221-en
  • resource tags

    arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:06

General

  • Target

    e90287a2048da1d5a4bcc4723399f4c7e25473b967a6d8b3cb336871af337ab6.exe

  • Size

    94KB

  • MD5

    c4a25c40782d21c86a24cdc2a31a21de

  • SHA1

    f24242a84b2371b9d9507749a3ad2ada873aea28

  • SHA256

    e90287a2048da1d5a4bcc4723399f4c7e25473b967a6d8b3cb336871af337ab6

  • SHA512

    c934def64ec32ba4b7a46f4170001e1e5c33503e7beb4e73f998b2b4a977357483bae119534c1927de8689c00662ce168cd1f5d4562e4f7831e8cd504ed63151

  • SSDEEP

    1536:W7ZhA7pApMaxB4b0CYJ97lEVqNR7Yge+eJG/x/OfxRfxHAu39Au3lCT:6e7WpMaxeb0CYJ97lEYNR73e+eKZOf70

Score
9/10

Malware Config

Signatures

  • Renames multiple (3250) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\e90287a2048da1d5a4bcc4723399f4c7e25473b967a6d8b3cb336871af337ab6.exe
    "C:\Users\Admin\AppData\Local\Temp\e90287a2048da1d5a4bcc4723399f4c7e25473b967a6d8b3cb336871af337ab6.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2940

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2297530677-1229052932-2803917579-1000\desktop.ini.tmp
    Filesize

    94KB

    MD5

    771df25a88a9a736d7654902bd47b145

    SHA1

    02927e16501affbea053400eb6719cb82aedf523

    SHA256

    c8ea47fa931c2a76c077e20163047094f8296f456db824327d483a507012c8eb

    SHA512

    942b5d0a0f8af34e354786cf26f2b8ed33aab1ebddc7c3fde6290a82c2296d5930272c60494dd2e53d955a16ae1db1f8d07ccd4e204eb5e6158c21d131ea7197

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    103KB

    MD5

    481d9249b6f546532f05d5b3dcbe0f2f

    SHA1

    c50a529b34394b63ef8b7edf3e75c1c86cc09972

    SHA256

    258a4ecd7ec74f4eaf199ce3863afd28c128fe8bde50c394cfddfecfcbd32d1f

    SHA512

    2e1698ced685f6fd7d465a6240df3f1551695eb2a703f0cc10fd0bd36cf52fa7b77b3f0677bd47db0c4fd30c03931967b2b1ef4b503ae18bb28e5da9f50dfd14