Analysis

  • max time kernel
    150s
  • max time network
    98s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240508-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system
  • submitted
    01-07-2024 05:02

General

  • Target

    ffafc4c110ebb0a732919e7c328ebe208a700487d1d3ef229fda499c150bdc44.exe

  • Size

    46KB

  • MD5

    8ff30e0e2eeb28932789ada57c96bab3

  • SHA1

    364fc532ac06f389f1aebbee598373c0563da735

  • SHA256

    ffafc4c110ebb0a732919e7c328ebe208a700487d1d3ef229fda499c150bdc44

  • SHA512

    b47372b712be43d16c1995e09c26f101b1b97b1b48e24b1d1e8a13b6188ccfcbd7fc6120487e8329a9ad44396a080e974bc2c1d6c25a787748248c8a37ded371

  • SSDEEP

    768:kBT37CPKKIm0CAbLg++PJHJzIWD+dVdCYgck5sIZFlzc3/Sg2aDM9uA9DM9uAFz+:CTWn1++PJHJXA/OsIZfzc3/Q8zx4

Score
9/10

Malware Config

Signatures

  • Renames multiple (5021) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • UPX dump on OEP (original entry point) 4 IoCs
  • UPX packed file 4 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\ffafc4c110ebb0a732919e7c328ebe208a700487d1d3ef229fda499c150bdc44.exe
    "C:\Users\Admin\AppData\Local\Temp\ffafc4c110ebb0a732919e7c328ebe208a700487d1d3ef229fda499c150bdc44.exe"
    1⤵
    • Drops file in Program Files directory
    PID:4572

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.tmp
    Filesize

    46KB

    MD5

    a4080b3a3f88e711ac873112bf50b733

    SHA1

    3db0a91c252e7bae8ea06bf0f02fd812c45e69fb

    SHA256

    b74bcaab745df61485a5ab36d39a9a998124daaac8214a10df84e5b0f65b1e20

    SHA512

    a9dad819682afaf0e835a717824a7e9f7003abd09f70c8a0863efe5e1d8c664f0683acd48930100ce81543e4a602afa9b03c7f628496a427f99439bf555a4838

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    145KB

    MD5

    6c167ff35891a497f2857a0da1c81034

    SHA1

    e0974ff9a8996bf66ae9ab0bb4e0a2d85a87af49

    SHA256

    d33643705a3cb2bd160957fc4a2dfab6356ee7c2993bfda025d9195b6e926754

    SHA512

    5b38d7e52634be55838a61bf8d441f98175f95133e37978d5104c4f5e660825765604a1a26df978c330d7732e646a0a0256e2dcfe2b02df0383097c1651cba40

  • memory/4572-0-0x0000000000400000-0x000000000040A000-memory.dmp
    Filesize

    40KB

  • memory/4572-1082-0x0000000000400000-0x000000000040A000-memory.dmp
    Filesize

    40KB