| File name: | ransomware.bat |
| Full analysis: | https://app.any.run/tasks/e900b9b6-ba14-4c15-bb7a-9018df0df2ec |
| Verdict: | Malicious activity |
| Analysis date: | May 20, 2022, 21:20:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with CRLF line terminators |
| MD5: | D18922F0510DCBC6B17B6BA9C1DD5469 |
| SHA1: | 5C8FB787AEB3C3228B87CD4305851E6539CC7045 |
| SHA256: | 74AA3CEF6B9F311DAC31AA38CF9652D147DC5465D4196691CE86CF80B4452DCD |
| SSDEEP: | 6:hENekVCFl2IOhBGihl2tsNMN27YGPQyDC1gFoekVCFl2IOhhDA:LmCFdOhBGihlwcMaUyDCuVmCFdOhhc |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Opera\Opera\cache" "C:\Users\admin\AppData\Local\Opera\Opera\cache.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942405 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 188 | certutil -encode "C:\Users\admin\AppData\Local\Steam\htmlcache\Cache\data_1" "C:\Users\admin\AppData\Local\Steam\htmlcache\Cache\data_1.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 240 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 240 | certutil -encode "C:\Users\admin\AppData\Local\Google\Chrome\User" "C:\Users\admin\AppData\Local\Google\Chrome\User.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942402 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 240 | certutil -encode "C:\Users\admin\AppData\Local\Microsoft\Windows" "C:\Users\admin\AppData\Local\Microsoft\Windows.encrypted" | C:\Windows\system32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 2147942405 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1020 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_pole_null_100.png.encrypted | text | |
MD5:2E5A93891924E2FE4D994F60CD185A19 | SHA256:CD73EAE82F967E0538FC3677C871C14B466067B1B6124368AE12DE36A170A1D8 | |||
| 2108 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_pole_null_150.png.encrypted | text | |
MD5:A6ADE28B463D1EFA6D822FE74948DDFE | SHA256:F5C24A22DB5DA4DDE13CCC5B7BCD3930566CEF5D2937D84E199F93EDC9812846 | |||
| 1184 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_darkgray_base_200.png.encrypted | text | |
MD5:0224F5E2B78D3D76C36BD4E189032E9B | SHA256:FC9D6F9CF09C1169C82B8932C9B45F624DC671013BA096D8ABCA9D225D29620F | |||
| 3456 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gccheck_small.exe.encrypted | text | |
MD5:6091A8D908627069B301F8779F34169C | SHA256:A561A05C706647D2F79E5E917412A5BBAA12F29842D168434647C1E0E7649D6C | |||
| 2468 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_150.png.encrypted | text | |
MD5:D3B8E410271711E2789307ADEDB9A304 | SHA256:CFB167CBC06A7219A8FA6C7D13B05F0C61CCD817E9278C663462285D41145BB2 | |||
| 328 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_pole_null_125.png.encrypted | text | |
MD5:2644D99AD4F6B5262A54B1FAED82FB8E | SHA256:D2C3B0040718B9DAF7A07D197254D4096DE0AB3B49943242C34125C8D43FEEFA | |||
| 3596 | certutil.exe | C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT.encrypted | text | |
MD5:3D441FE7E7BE7E2B8DCB61C70B4F495E | SHA256:E9F7C8E7C61B34C54508232D30B009C55118A543249669476D8BEE18694ED8C1 | |||
| 2560 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_125.png.encrypted | text | |
MD5:2FAC639D946A52EBBA199D191BEF414A | SHA256:3A4EA647EB35FC9CD578615F0B48E95759D84238261B252A1B892EDC6409307C | |||
| 2876 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_200.png.encrypted | text | |
MD5:0D143DC106344A05B6DB9BB026D4D59A | SHA256:A384BECA3F348887970125CBB983936DFCD361F29CAFBBB468AFCF94862350B3 | |||
| 3532 | certutil.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_darkgray_base_100.png.encrypted | text | |
MD5:67311D9AE3C0581D58823A5727983905 | SHA256:136A5370A49C29608B2DD4AF5A4CA9E81EF64728EA2DE8BF48E9443C4AE9FE29 | |||