General

  • Target

    eaa002d681dadb4e6c7cbb185d62776cd1313bea829e1d7d32667588fbad8a7c

  • Size

    172KB

  • Sample

    240701-es1bmswcjh

  • MD5

    965c2372e03bb737eecdcfdbe74d612f

  • SHA1

    b7abf860328974910755e4c7e452e06315aea681

  • SHA256

    eaa002d681dadb4e6c7cbb185d62776cd1313bea829e1d7d32667588fbad8a7c

  • SHA512

    994fba9969c595e1818d4f814019a0d45dfbfcf73a56a227f7f373b4681180f8021b12f763ac06594534b4d808a6ca75866353e5c7f1cc3110d76f56160a3e33

  • SSDEEP

    3072:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFslEhLfyBf:PqFF2Ie+eFC2WqFF2Ie+eFC2/

Score
9/10

Malware Config

Targets

    • Target

      eaa002d681dadb4e6c7cbb185d62776cd1313bea829e1d7d32667588fbad8a7c

    • Size

      172KB

    • MD5

      965c2372e03bb737eecdcfdbe74d612f

    • SHA1

      b7abf860328974910755e4c7e452e06315aea681

    • SHA256

      eaa002d681dadb4e6c7cbb185d62776cd1313bea829e1d7d32667588fbad8a7c

    • SHA512

      994fba9969c595e1818d4f814019a0d45dfbfcf73a56a227f7f373b4681180f8021b12f763ac06594534b4d808a6ca75866353e5c7f1cc3110d76f56160a3e33

    • SSDEEP

      3072:6pWpUFpEhLfyBtPf50FWkFpPDze/qFsxEhLfyBtPf50FWkFpPDze/qFslEhLfyBf:PqFF2Ie+eFC2WqFF2Ie+eFC2/

    Score
    9/10
    • Renames multiple (3388) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Executes dropped EXE

    • Loads dropped DLL

    • Drops file in System32 directory

MITRE ATT&CK Matrix

Tasks