Analysis

  • max time kernel
    149s
  • max time network
    152s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 04:14

General

  • Target

    eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe

  • Size

    78KB

  • MD5

    ece6f209e287deef248f5452ed66eac2

  • SHA1

    3243bc0aa2249a4d59910cee1e6b925f04ce5845

  • SHA256

    eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684

  • SHA512

    f66f87b657adcb421b014345dd9476f45a5a2071edfc3358019d7a2f53640141bd31e1293272d0a3c81c5d1168dd378cd0723b73445d3d7f1ceef6ab22f5058c

  • SSDEEP

    1536:V7Zf/FAxTWY1++PJHJXA/OsIZfzc3/Q8zxZfxRfxy:fnyiQSoWf7fM

Score
9/10

Malware Config

Signatures

  • Renames multiple (4887) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • UPX packed file 4 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe
    "C:\Users\Admin\AppData\Local\Temp\eb31344c5978002527314547b5f80e303429f554643853bc5b9dddbf26ba3684.exe"
    1⤵
    • Drops file in Program Files directory
    PID:1604

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-1337824034-2731376981-3755436523-1000\desktop.ini.tmp
    Filesize

    78KB

    MD5

    c6b7b012c987cb24420558799dbe953c

    SHA1

    1663f41f37a17a648db4e1982fd6bcaf157d2852

    SHA256

    2776ee892313dc104cac01bce05620623a21ee65a36a9376d0adfd6bbec58177

    SHA512

    6797fd24c89be34e034e38b728c8db4feb791deb0c6c7cc9aae5ab9591d448f13a5f66f973b0a53b8d148d70b4c872166ec88b2f5e3a7e7dff9911d619f84217

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    177KB

    MD5

    8eb049f3ff8f4d28eca471fc4ee507d7

    SHA1

    593799b65803745f6006e7a5f5e22557b5027be9

    SHA256

    be20b335856c01a3dd3cd84872bfe27eb6188005860f0a1ff773c321d28cfadf

    SHA512

    e7ce766398e242341a098a1a14988637ed3c0e03a42200c4b7f89c9233337160ddfb9f3e144f0f44846c84934613c931e23cfee04be09e070740054874d2697b

  • memory/1604-0-0x0000000000400000-0x000000000040B000-memory.dmp
    Filesize

    44KB

  • memory/1604-1782-0x0000000000400000-0x000000000040B000-memory.dmp
    Filesize

    44KB