Analysis

  • max time kernel
    139s
  • max time network
    123s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:15

General

  • Target

    eb74e36ae8bacbcd8a70eb53aeb75b622c8f13f0744f0c94efd75584c309b3c1.exe

  • Size

    62KB

  • MD5

    5afb68ee7cc4d421ca318acca8fe8a5c

  • SHA1

    f67049b49a72d0277db17a6f70152e9e4027be52

  • SHA256

    eb74e36ae8bacbcd8a70eb53aeb75b622c8f13f0744f0c94efd75584c309b3c1

  • SHA512

    badc24f9e3a6bb340e00a6a2c737522a1ccc78cbdd2afa71cd743aa173f146cfeb2092af297d6247c120939ca851b8d2c0aa1dd9009c1db9d12ba6213a526bcf

  • SSDEEP

    768:/7BlpQpARFbhIYJIJDYJIJPfFpsJcFfFpsJcC+3mC+3meD1:/7ZQpApze+eJfFpsJOfFpsJ5D1

Score
9/10

Malware Config

Signatures

  • Renames multiple (3151) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\eb74e36ae8bacbcd8a70eb53aeb75b622c8f13f0744f0c94efd75584c309b3c1.exe
    "C:\Users\Admin\AppData\Local\Temp\eb74e36ae8bacbcd8a70eb53aeb75b622c8f13f0744f0c94efd75584c309b3c1.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1724

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-268080393-3149932598-1824759070-1000\desktop.ini.tmp
    Filesize

    62KB

    MD5

    4b7f27718ebdfdfd8f2573f6fdf8e27a

    SHA1

    ee236d6e93788d60bada0e561b0567328200450e

    SHA256

    eb1277a38132b5915bd72f366156e000e77041d430ccb37f53b35b9744d84879

    SHA512

    24005935a6286d727981c52e46ba4ac024f59ae44ba7793f8b08299979d8075b9b630e079a5a1a729de3dcc96c2ddbda50536d326c9e2b21975e917d0d0dca93

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    71KB

    MD5

    3bba1abea40b0eddc29f27d284f0f964

    SHA1

    4c43ed2a01d245c2603f0ede9e4705390dea71db

    SHA256

    2f1b10736093352b61d41c0fd240c3fc80b1fe337ba8960a8a08bf3119a410b7

    SHA512

    1d9657a2bd10fbb306ca91e43c7629431415be84d590b86a60e9b3206be4d0727c868265618ad083515875fc086dff4c94c95aeed6489f7231fd1849f9845bc7

  • memory/1724-0-0x0000000000400000-0x0000000000408000-memory.dmp
    Filesize

    32KB

  • memory/1724-306-0x0000000000400000-0x0000000000408000-memory.dmp
    Filesize

    32KB