File name:

2773e3dc59472296cb0024ba7715a64e.exe

Full analysis: https://app.any.run/tasks/a4a491ad-8b6f-4c9d-a60a-95cc0bfafd36
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: December 14, 2024, 03:26:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
jigsaw
ransomware
confuser
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 5 sections
MD5:

2773E3DC59472296CB0024BA7715A64E

SHA1:

27D99FBCA067F478BB91CDBCB92F13A828B00859

SHA256:

3AE96F73D805E1D3995253DB4D910300D8442EA603737A1428B613061E7F61E7

SSDEEP:

6144:7fukPLPvucHiQQQ4uuy9ApZbZWxcZt+kTfMLJTOAZiYSXjjeqXusy:7fu5cCT7yYlWi8kTfMLJTOAZiYSXjyqO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RANSOMWARE has been detected

      • drpbx.exe (PID: 6308)
    • Changes the autorun value in the registry

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • JIGSAW has been detected

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Starts itself from another location

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Reads the date of Windows installation

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Executable content was dropped or overwritten

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Creates file in the systems drive root

      • drpbx.exe (PID: 6308)
  • INFO

    • Creates files or folders in the user directory

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Reads the computer name

      • drpbx.exe (PID: 6308)
      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Reads the machine GUID from the registry

      • drpbx.exe (PID: 6308)
    • Checks supported languages

      • drpbx.exe (PID: 6308)
      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Process checks computer location settings

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • The process uses the downloaded file

      • 2773e3dc59472296cb0024ba7715a64e.exe (PID: 2072)
    • Creates files in the program directory

      • drpbx.exe (PID: 6308)
    • Confuser has been detected (YARA)

      • drpbx.exe (PID: 6308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (61.6)
.dll | Win32 Dynamic Link Library (generic) (14.6)
.exe | Win32 Executable (generic) (10)
.exe | Win16/32 Executable Delphi generic (4.6)
.exe | Generic Win/DOS Executable (4.4)

EXIF

EXE

AssemblyVersion: 37.0.2.5583
ProductVersion: 37.0.2.5583
ProductName: Firefox
OriginalFileName: BitcoinBlackmailer.exe
LegalTrademarks: -
LegalCopyright: Copyright 1999-2012 Firefox and Mozzilla developers. All rights reserved.
InternalName: BitcoinBlackmailer.exe
FileVersion: 37.0.2.5583
FileDescription: Firefox
CompanyName: -
Comments: -
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 37.0.2.5583
FileVersionNumber: 37.0.2.5583
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x4e00a
UninitializedDataSize: -
InitializedDataSize: 216576
CodeSize: 72704
LinkerVersion: 8
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2016:03:31 06:28:14+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #JIGSAW 2773e3dc59472296cb0024ba7715a64e.exe THREAT drpbx.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2072"C:\Users\admin\AppData\Local\Temp\2773e3dc59472296cb0024ba7715a64e.exe" C:\Users\admin\AppData\Local\Temp\2773e3dc59472296cb0024ba7715a64e.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
37.0.2.5583
Modules
Images
c:\users\admin\appdata\local\temp\2773e3dc59472296cb0024ba7715a64e.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6308"C:\Users\admin\AppData\Local\Drpbx\drpbx.exe" C:\Users\admin\AppData\Local\Temp\2773e3dc59472296cb0024ba7715a64e.exeC:\Users\admin\AppData\Local\Drpbx\drpbx.exe
2773e3dc59472296cb0024ba7715a64e.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Firefox
Version:
37.0.2.5583
Modules
Images
c:\users\admin\appdata\local\drpbx\drpbx.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
7 839
Read events
7 838
Write events
1
Delete events
0

Modification events

(PID) Process:(2072) 2773e3dc59472296cb0024ba7715a64e.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:firefox.exe
Value:
C:\Users\admin\AppData\Roaming\Frfx\firefox.exe
Executable files
2
Suspicious files
19
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6308drpbx.exeC:\Users\admin\Desktop\involvedclients.rtf.funbinary
MD5:DB080A9FEF5F16BE602F68E4F5BDAF16
SHA256:60F5061F13C2ABFA3677016B410C101D1FB40357C06953E4EE806F58C9FDBA61
6308drpbx.exeC:\Users\admin\Desktop\newsletterconsider.rtf.funbinary
MD5:7DA9A57E3C8FB0A1BAEC9D56732CE40A
SHA256:014E3352D5FB1965AE8D7F034BB4FFB6885D2F203D5E51430028602719B28BD9
6308drpbx.exeC:\Users\admin\Desktop\lifeest.png.funbinary
MD5:2963517B9D6B5AF6934EF666AF2A2730
SHA256:1646F447D4DF08CC2A8834EB6D7E6458D3BE10DF355E2B2BF5A497B51E457A0A
6308drpbx.exeC:\Users\admin\Desktop\accessfree.jpg.funbinary
MD5:AD3DFB545E2C1C43B25A12024E44E5F0
SHA256:3A8BA0FC48F68A7DCFC35C7508D9CF66C80975640C9AB77A9387EB745F67023D
6308drpbx.exeC:\Users\admin\Pictures\russianusing.jpg.funbinary
MD5:18E5C44B6D2BD315E980A7A8A8A39460
SHA256:B186273DD524C2D52C93F9BBCE7E2A92EAD8D698D40E8C46F836BC7923FEE8E6
6308drpbx.exeC:\Users\admin\Documents\giftsinstead.rtf.funbinary
MD5:4898EF44E5433FF552E4CE07891A1C09
SHA256:C5E4D9C944AE6D8725D9574B534BB7B2B862F496E89F61BAEAA7C739699987FC
6308drpbx.exeC:\Users\admin\Documents\featureswelcome.rtf.funbinary
MD5:1B69017D7020BBA1F57BFC474564FC15
SHA256:803904791B21B04B1D867E8F0F612833C1A401A43C8C22400E0A156DAF27B9C0
6308drpbx.exeC:\Users\admin\Documents\softwaresuccess.rtf.funbinary
MD5:FFDE30710DD59B55152D9E395B84A7AD
SHA256:C3C0D19CF29B84ED6AAA727913BE2E376BB3950D77D3AB6553BC767378DB7AEF
6308drpbx.exeC:\Users\admin\Desktop\certificatexxx.rtf.funbinary
MD5:05852C386A8048E454D2AC98FE0E814B
SHA256:18121940EEB11AB1D9CCFE0E502D4DDF1E97246760932F85ACD6388FF7DE2470
6308drpbx.exeC:\Users\admin\Desktop\sureusers.png.funbinary
MD5:47C396EDEBB168FD0F90D9DD100CC264
SHA256:964F0BA76F779C05E0F367164AFB24476A093E42258B868238B4D1FC03594D65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
33
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7108
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7108
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.96.107:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.bing.com
  • 2.19.96.107
  • 2.19.96.128
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.73
  • 20.190.159.0
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info