General

  • Target

    2024-07-01_0ad4f1567592a3d73ec61e461f7bce4c_darkside

  • Size

    150KB

  • Sample

    240701-eyt2tazakq

  • MD5

    0ad4f1567592a3d73ec61e461f7bce4c

  • SHA1

    842ba1ad3799c0e65dafce7e71c0f4585e26443f

  • SHA256

    5fc30ad2bc0d586a9b21fab26e66ef52ace6eb7ce7fc22c3a693a9ec9669ae05

  • SHA512

    99cc76d1e5ca57aeeaea2154587a95b8e043c9e713636f93574945cf25cafa76cd1a8a7f4ff72e2244c3ff26220aecbc1df76dc791468142baa601c4a7f19b5d

  • SSDEEP

    3072:g6glyuxE4GsUPnliByocWepeKNHOpEu/vpmtO:g6gDBGpvEByocWegUWZ

Malware Config

Extracted

Path

C:\3wHht2h41.README.txt

Ransom Note
+-----------------------------------------------------------------------------------------------------------------------------------------------+ | --> WARNING <-- | | Your data are stolen and encrypted! | | | | The data will be published on ONION website if you do not pay the ransom! | | | | What guarantees that we won't cheat you? | | | | We are not interested in politics. We are interested in money! | | | | Once you pay for the decryption program, we will give it to you immediately, it is fully automatic. | | Life is too short to be sad. Don't be sad, money is just paper. | | | | We're just as interested in giving you the program. | | Our reputation is very important to us. We attack companies all over the world, and there is not a single dissatisfied victim after payment.| | | | You can send us a file up to 5 megabyte in size and we will decrypt it for free. | | | | You need to contact us by email: | | | -> [email protected] | -> [email protected] | | | | Your personal DECRYPTION MASTER_ID: F7B87B84AFBCA1B1A0E885C51CB2AB8C | | | | Warning! Do not DELETE or MODIFY any files | | | +-----------------------------------------------------------------------------------------------------------------------------------------------+

Extracted

Path

C:\3wHht2h41.README.txt

Ransom Note
+-----------------------------------------------------------------------------------------------------------------------------------------------+ | --> WARNING <-- | | Your data are stolen and encrypted! | | | | The data will be published on ONION website if you do not pay the ransom! | | | | What guarantees that we won't cheat you? | | | | We are not interested in politics. We are interested in money! | | | | Once you pay for the decryption program, we will give it to you immediately, it is fully automatic. | | Life is too short to be sad. Don't be sad, money is just paper. | | | | We're just as interested in giving you the program. | | Our reputation is very important to us. We attack companies all over the world, and there is not a single dissatisfied victim after payment.| | | | You can send us a file up to 5 megabyte in size and we will decrypt it for free. | | | | You need to contact us by email: | | | -> [email protected] | -> [email protected] | | | | Your personal DECRYPTION MASTER_ID: F7B87B84AFBCA1B10645C837638D3FB9 | | | | Warning! Do not DELETE or MODIFY any files | | | +-----------------------------------------------------------------------------------------------------------------------------------------------+

Targets

    • Target

      2024-07-01_0ad4f1567592a3d73ec61e461f7bce4c_darkside

    • Size

      150KB

    • MD5

      0ad4f1567592a3d73ec61e461f7bce4c

    • SHA1

      842ba1ad3799c0e65dafce7e71c0f4585e26443f

    • SHA256

      5fc30ad2bc0d586a9b21fab26e66ef52ace6eb7ce7fc22c3a693a9ec9669ae05

    • SHA512

      99cc76d1e5ca57aeeaea2154587a95b8e043c9e713636f93574945cf25cafa76cd1a8a7f4ff72e2244c3ff26220aecbc1df76dc791468142baa601c4a7f19b5d

    • SSDEEP

      3072:g6glyuxE4GsUPnliByocWepeKNHOpEu/vpmtO:g6gDBGpvEByocWegUWZ

    • Renames multiple (366) files with added filename extension

      This suggests ransomware activity of encrypting all the files on the system.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Drops desktop.ini file(s)

    • Suspicious use of NtSetInformationThreadHideFromDebugger

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

1
T1552

Credentials In Files

1
T1552.001

Collection

Data from Local System

1
T1005

Tasks