Analysis

  • max time kernel
    150s
  • max time network
    130s
  • platform
    windows10-2004_x64
  • resource
    win10v2004-20240704-en
  • resource tags

    arch:x64arch:x86image:win10v2004-20240704-enlocale:en-usos:windows10-2004-x64system
  • submitted
    05-07-2024 04:28

General

  • Target

    eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe

  • Size

    39KB

  • MD5

    7b5844a39a0193bb0e9e5667bb0726cd

  • SHA1

    bb0b1d3939c30b8e36486922187312f0aee4f722

  • SHA256

    eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781

  • SHA512

    f1e6bbe530ddb14f9fc5621d2e9ae2bcee4df8704874b7bcdba9dae0ef8480f5e76e9e8780b04f8ddda6628fc3a9418bc76a745b78642a2488abdf1958a690a6

  • SSDEEP

    768:W7BlpppARFbhFAVo7FOtiJw1OtiJfo7FOtiJw1OtiJWHAJxBHAJxo:W7ZppAp1IWI7

Score
9/10

Malware Config

Signatures

  • Renames multiple (3859) files with added filename extension

    This suggests ransomware activity of encrypting all the files on the system.

  • Drops file in Program Files directory 64 IoCs

Processes

  • C:\Users\Admin\AppData\Local\Temp\eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe
    "C:\Users\Admin\AppData\Local\Temp\eed06183662a5df47d9c9cbed0b0eceed1cdc9e33db293c90d0d3ace89d1a781.exe"
    1⤵
    • Drops file in Program Files directory
    PID:2372

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • C:\$Recycle.Bin\S-1-5-21-2494989678-839960665-2515455429-1000\desktop.ini.tmp
    Filesize

    40KB

    MD5

    ffa3ff312b89d8df9d3ac6c44e9219f9

    SHA1

    f02f54f290bb78868f330409c9cd86370b27f1ef

    SHA256

    e2987c090fae17ceabf4cc1785e2d4c704c3f217fd2a77ee7339b18d8586d33a

    SHA512

    af3879427bcfefaa2163d58775e25a93debaa6c66d997f1e98b48aff0e96cdada44daa0be4c89edf5526533848eb1553fe2443c74f18b554ed211b44c0a63c6a

  • C:\Program Files\7-Zip\7-zip.dll.tmp
    Filesize

    138KB

    MD5

    501202945377041b62a6a3c3b35502e8

    SHA1

    e2966869650862cc53aca64f452aee874434965a

    SHA256

    e06099b6123e314775a94da5db6943b1f41317490a0beebf7473f88683518308

    SHA512

    aed8f07975b6c5708f0852c08b679174fa332b3374bea2cf0a0e86e53ce567afeb299ecd84275c812cda21c846db548f62f48f51fd4a69f7965b25366eebcbf3