Analysis

  • max time kernel
    150s
  • max time network
    19s
  • platform
    windows7_x64
  • resource
    win7-20240704-en
  • resource tags

    arch:x64arch:x86image:win7-20240704-enlocale:en-usos:windows7-x64system
  • submitted
    05-07-2024 04:28

General

  • Target

    eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe

  • Size

    39KB

  • MD5

    7b5844a39a0193bb0e9e5667bb0726cd

  • SHA1

    bb0b1d3939c30b8e36486922187312f0aee4f722

  • SHA256

    eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781

  • SHA512

    f1e6bbe530ddb14f9fc5621d2e9ae2bcee4df8704874b7bcdba9dae0ef8480f5e76e9e8780b04f8ddda6628fc3a9418bc76a745b78642a2488abdf1958a690a6

  • SSDEEP

    768:W7BlpppARFbhFAVo7FOtiJw1OtiJfo7FOtiJw1OtiJWHAJxBHAJxo:W7ZppAp1IWI7

Score
9/10

Malware Config

Signatures

  • Renames multiple (560) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe
    "C:\Users\Admin\AppData\Local\Temp\eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2348

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2212144002-1172735686-1556890956-1000\desktop.ini.tmp
    Filesize

    40KB

    MD5

    9a9cf31a424e6c4adc12f2361aed3e7c

    SHA1

    8398701c2fff5f2fda781e2f487596f9466ec2f5

    SHA256

    c772a7138d336b98a9096402619f8a355235b5a25a210ed7ec99a3954613281f

    SHA512

    61b7d15881bec10cfb9500fe2d1d78616d1f1367d936f6f31622b0391acac8b8ebd6dceb61095a60e8e4b99c03bbbb50097cd05574b62b33eb0f52e0a667526f

  • C:\MSOCache\All Users\{90140000-0011-0000-0000-0000000FF1CE}-C\Office64WW.xml.tmp
    Filesize

    48KB

    MD5

    1de84d135fc7c11728d44ae2dc2d1c57

    SHA1

    96903667b99b6b53b798a892b6c141d4a386bca1

    SHA256

    5f1b006cbcb04f625592a445bfe6955142ef3e693b471a5e371100bde14671dc

    SHA512

    196cbb4d795a10161077c681bc8bfa36f822b6ed3315b3ecc5b26546a4288d40f036d26f44cee5a7e2071ac32923b9a147673f9d595bb2f3c83ee39900c2e814