Analysis

  • max time kernel
    150s
  • max time network
    122s
  • platform
    windows7_x64
  • resource
    win7-20240508-en
  • resource tags

    arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:14

General

  • Target

    eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe

  • Size

    78KB

  • MD5

    ece6f209e287deef248f5452ed66eac2

  • SHA1

    3243bc0aa2249a4d59910cee1e6b925f04ce5845

  • SHA256

    eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684

  • SHA512

    f66f87b657adcb421b014345dd9476f45a5a2071edfc3358019d7a2f53640141bd31e1293272d0a3c81c5d1168dd378cd0723b73445d3d7f1ceef6ab22f5058c

  • SSDEEP

    1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8zxZfxRfxy:fnyiQSoWf7fM

Score
9/10

Malware Config

Signatures

  • Renames multiple (3309) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • UPX packed file 4 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe
    "C:\Users\Admin\AppData\Local\Temp\eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1992

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-268080393-3149932598-1824759070-1000\desktop.ini.tmp
    Filesize

    78KB

    MD5

    6db4137fe943fb131683ad5bf24d85f3

    SHA1

    2ddc7622ed2dbd8b04090722f74ebd545c311c78

    SHA256

    cdaf9dd43a5042573ac414911b3ab9a2b5add24d59a3c52d4ea398634bc11484

    SHA512

    598d0d6636ca050401afb1cf619c76cd7773812670dbf8ea3a4a9565fb26419cde70930c0fb4782c44fbca5141600848a1de406d7e9092aa82a51dc422130142

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    87KB

    MD5

    17066850db9ef2cef3043b0d58edcb84

    SHA1

    5044daebb0116d7bc2f64d1b6edd0378ddc2cdef

    SHA256

    93a63fc77852b584d66ba5106e6baac2df2b46b96b1adf8665dccab1b828fd7f

    SHA512

    a74fde4daad542c72c3bcca7174406f2297157f79c6760faf6484257d0bd3399ff9849549c4661a75c2b2654ccd98965d2adb2f542e42dfbdaf8486f9229a741

  • memory/1992-0-0x0000000000400000-0x000000000040B000-memory.dmp
    Filesize

    44KB

  • memory/1992-308-0x0000000000400000-0x000000000040B000-memory.dmp
    Filesize

    44KB