File name: | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe |
Full analysis: | https://app.any.run/tasks/e33e5d62-fa9d-41eb-b0d0-14b1c2b2311a |
Verdict: | Malicious activity |
Threats: | LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations. |
Analysis date: | December 14, 2024, 11:47:54 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
MD5: | EB13533A89DA9762D93DE5D54966DF5F |
SHA1: | C0D2CEF9149395218EB3A91AFE6CBBDBF0181C65 |
SHA256: | 3DC6902DC87D976787BDF0878E7174EC526DF613645D3F275E0216D05CF2D217 |
SSDEEP: | 12288:rgnL2oPQoPq2Doa2ieRwN6TPqqXc1lPy+mUP1mjqS9mXishlj8Wsu:epxPZeR66TPFXciMsqSA9su |
.exe | | | Win64 Executable (generic) (87.3) |
---|---|---|
.exe | | | Generic Win/DOS Executable (6.3) |
.exe | | | DOS Executable Generic (6.3) |
Subsystem: | Windows GUI |
---|---|
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x4cc70 |
UninitializedDataSize: | - |
InitializedDataSize: | 139776 |
CodeSize: | 484864 |
LinkerVersion: | 14.39 |
PEType: | PE32+ |
ImageFileCharacteristics: | Executable, Large address aware |
TimeStamp: | 2024:10:15 09:41:32+00:00 |
MachineType: | AMD AMD64 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
4804 | "C:\Users\admin\Desktop\3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe" | C:\Users\admin\Desktop\3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
4708 | "C:\Windows\System32\cmd.exe" /c SCHTASKS.exe /Create /RU "NT AUTHORITY\SYSTEM" /sc onstart /TN "Windows Update ALPHV" /TR "C:\Users\admin\Desktop\3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe" /F | C:\Windows\System32\cmd.exe | — | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
4652 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1856 | SCHTASKS.exe /Create /RU "NT AUTHORITY\SYSTEM" /sc onstart /TN "Windows Update ALPHV" /TR "C:\Users\admin\Desktop\3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe" /F | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Mozilla Firefox\omni.ja | — | |
MD5:— | SHA256:— | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst | binary | |
MD5:78B5108B43BC9AFB295B5CF957B37BFB | SHA256:A7C96708C01CEF6ABC071E28E52D39A12F10F50B254307FCA88E802A65EC8E1F | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst | binary | |
MD5:DB173910A9EA4544C8A37AB6BC0687FA | SHA256:0A65C3F756558C32E50FEBB2D46ADB25F107EABDB70FB28A402096EDBFBE7CB7 | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst.[ID-35AEE360].[[email protected]].Sauron | binary | |
MD5:DB173910A9EA4544C8A37AB6BC0687FA | SHA256:0A65C3F756558C32E50FEBB2D46ADB25F107EABDB70FB28A402096EDBFBE7CB7 | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash | binary | |
MD5:474B43281021A2DB604BBBE4D46DD120 | SHA256:7A2D91DA4506B5FF1544B755C8068925B3E437C3775BCBF5B0917F0F7DBCAEA2 | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.man | binary | |
MD5:4AF3A5AF4544C8F0DA68C3E51E6AD172 | SHA256:D878FD80713645188D16F88107D9AE08B88187BFEE48DDBB0E623237E2D8AB3E | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgrschedule.xml | binary | |
MD5:AC35A7E0CD8F3FD125D4986C638450D2 | SHA256:AFBBE48F0DA5776AF9AA48BE5F323C69A950FCDC8A806F892B66A8E863D07CFB | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | binary | |
MD5:01B1C00297C2A4946D84048B06BE2F5C | SHA256:2EF7BE18AFF9230FAABBDD6DAD3B83C0BDFACC9CABD9AF0124EF437C35A26844 | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClient.man | binary | |
MD5:8603102E7B1CC5E48734D19B2C32DF31 | SHA256:0A1900FA6E2BA57AA6568EB6AF243EC2220000F91361D238D4077C13689CED98 | |||
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.cab.cat | binary | |
MD5:3FFCDABB550497EDFF891B79541EAAB9 | SHA256:88CE1E2A0A05C1FBC956862EEE50B81D282813AFDD99CFDDDDE2A32A4C90D0A4 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | 192.168.100.2:445 | — | — | — | whitelisted |
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | 192.168.100.1:445 | — | — | — | unknown |
3976 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6092 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4804 | 3dc6902dc87d976787bdf0878e7174ec526df613645d3f275e0216d05cf2d217.exe | 192.168.100.198:445 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |