Analysis

  • max time kernel
    150s
  • max time network
    117s
  • platform
    windows7_x64
  • resource
    win7-20240611-en
  • resource tags

    arch:x64arch:x86image:win7-20240611-enlocale:en-usos:windows7-x64system
  • submitted
    01-07-2024 04:42

General

  • Target

    f66ac961527c2cc61826f194135fcb9b85622178fe0024ba5b05fac2bf34a378.exe

  • Size

    59KB

  • MD5

    749a0ccf968cedd9704e26c15004bfd6

  • SHA1

    6236ab477c0a00d5f140bff16bed86136ceb1258

  • SHA256

    f66ac961527c2cc61826f194135fcb9b85622178fe0024ba5b05fac2bf34a378

  • SHA512

    9bf150a023bb97d6c9b59985ecda6658a108abe6b620e8ce453933ac1a707a6e66bbd8072290aa3831772d290b37638f1b92e4c192bc0ac7129262735af23977

  • SSDEEP

    1536:CTWn1++PJHJXA/OsIZfzc3/Q8IZZ7n97nV:KQSo7ZFZV

Score
9/10

Malware Config

Signatures

  • Renames multiple (3487) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • UPX dump on OEP (original entry point) 4 IoCs
  • UPX packed file 4 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\f66ac961527c2cc61826f194135fcb9b85622178fe0024ba5b05fac2bf34a378.exe
    "C:\Users\Admin\AppData\Local\Temp\f66ac961527c2cc61826f194135fcb9b85622178fe0024ba5b05fac2bf34a378.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2452

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2812790648-3157963462-487717889-1000\desktop.ini.tmp
    Filesize

    59KB

    MD5

    002dfa6cd689e2ab588a19039f759228

    SHA1

    babc3544dffe3bb1b81ea9ec6b8f5668fcf625e9

    SHA256

    5f8ea76c0a32fa666d002dddc0b4a3da8e39375737710d3cd130d680a75d2c08

    SHA512

    da6a5650d725b8f3051906d2e5fa24dfe806e71b2a94368d076b98530042a2329eabe4a5bc137cfaf5e216526cd4c35b9bca84e081bbde740e31c02eb5169f74

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    68KB

    MD5

    5add559c361224609d567ca9d9bf0a76

    SHA1

    eeef9fdc5850423f61d5b82793e0725207b9be86

    SHA256

    3dfa1522a933f3bfa0e4bb91beb3ab9637ce1c64408ad9d4e07fbfab34ae8c4e

    SHA512

    52b09a39ee931b4db1663d4683c55492d914d97ee502ac7f928dfe62bf40adae8982349254bc10e17cb01c76f7265e1235f1c735bd137b33c4192b12b14e5124

  • memory/2452-0-0x0000000000400000-0x000000000040A000-memory.dmp
    Filesize

    40KB

  • memory/2452-76-0x0000000000400000-0x000000000040A000-memory.dmp
    Filesize

    40KB