| File name: | Chaos Ransomware Builder v4.exe |
| Full analysis: | https://app.any.run/tasks/64eb3af3-2b54-408e-bf35-7b6b157aefc3 |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2024, 20:00:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 8B855E56E41A6E10D28522A20C1E0341 |
| SHA1: | 17EA75272CFE3749C6727388FD444D2C970F9D01 |
| SHA256: | F2665F89BA53ABD3DEB81988C0D5194992214053E77FC89B98B64A31A7504D77 |
| SSDEEP: | 3072:9UJAYdi2YcRVm16Pn6tpzqJG/sX9i2YcRPm16Pn6ckCjSH5EyR9aKZt18rTu+i21:9aiWm162qJEsNiym16ryAiym168m |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:08:04 07:08:22+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 439808 |
| InitializedDataSize: | 123392 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6d5ae |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.0.0 |
| ProductVersionNumber: | 3.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileDescription: | Chaos Ransomware v4 |
| FileVersion: | 3.0.0.0 |
| InternalName: | Chaos Ransomware Builder v4.exe |
| LegalCopyright: | Copyright © 2021 |
| OriginalFileName: | Chaos Ransomware Builder v4.exe |
| ProductName: | Chaos Ransomware Builder v4 |
| ProductVersion: | 3.0.0.0 |
| AssemblyVersion: | 3.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Windows\System32\cmd.exe" /C bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no | C:\Windows\System32\cmd.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 532 | "C:\Users\admin\Desktop\Chaos Ransomware Builder v4.exe" | C:\Users\admin\Desktop\Chaos Ransomware Builder v4.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Chaos Ransomware v4 Exit code: 3221226540 Version: 3.0.0.0 Modules
| |||||||||||||||
| 764 | wbadmin delete catalog -quiet | C:\Windows\System32\wbadmin.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Command Line Interface for Microsoft® BLB Backup Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 840 | wmic shadowcopy delete | C:\Windows\System32\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1020 | C:\Windows\System32\vds.exe | C:\Windows\System32\vds.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Virtual Disk Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1196 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\2i230v5p\2i230v5p.cmdline" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | Chaos Ransomware Builder v4.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1368 | "C:\Windows\System32\cmd.exe" /C vssadmin delete shadows /all /quiet & wmic shadowcopy delete | C:\Windows\System32\cmd.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1572 | "C:\Users\admin\AppData\Roaming\svchost.exe" | C:\Users\admin\AppData\Roaming\svchost.exe | fack.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Exit code: 4294967295 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1608 | bcdedit /set {default} recoveryenabled no | C:\Windows\System32\bcdedit.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1636 | "C:\Windows\system32\wbengine.exe" | C:\Windows\System32\wbengine.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Block Level Backup Engine Service EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
| Operation: | write | Name: | 4 |
Value: 4300680061006F0073002000520061006E0073006F006D00770061007200650020004200750069006C0064006500720020002000760034002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 07000000020000000100000006000000000000000B0000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU |
| Operation: | write | Name: | 3 |
Value: 4300680061006F0073002000520061006E0073006F006D00770061007200650020004200750069006C0064006500720020002000760034002E0065007800650000000000 | |||
| (PID) Process: | (2848) Chaos Ransomware Builder v4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU |
| Operation: | write | Name: | MRUListEx |
Value: 03000000000000000200000001000000FFFFFFFF | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | Chaos Ransomware Builder v4.exe | C:\Users\admin\AppData\Local\Temp\eotvzn2z\eotvzn2z.0.cs | text | |
MD5:ADB72B9DD908446B2A980761A632360A | SHA256:07E1B8A2222EC2E1EB5E6B65F1345CEF699B800FBFAF371AB67FA78EF9982AA5 | |||
| 2648 | csc.exe | C:\Users\admin\Desktop\fack.exe | executable | |
MD5:522B96970CF31853D040D533EC6E2DD2 | SHA256:1B4DFBB39931D7185EFE7A8EC165A48E1848643186A7C92E93EB0E3B80D1DE69 | |||
| 2572 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESBF44.tmp | o | |
MD5:EE7BA0BD687E020BF93317BCDB410A36 | SHA256:6508401273E53BFB3AFDB75ABA043346042B8151240189346AADCE288AA45A0D | |||
| 2848 | Chaos Ransomware Builder v4.exe | C:\Users\admin\AppData\Local\Temp\eotvzn2z\eotvzn2z.cmdline | text | |
MD5:E62B575E57736D3DF97089D322EC4479 | SHA256:2470BF38A48109FED4106BF1FB4D41E26107A226A4E56C447FC6409933BE8D2C | |||
| 2648 | csc.exe | C:\Users\admin\AppData\Local\Temp\eotvzn2z\eotvzn2z.out | text | |
MD5:8B8FF5B8B766229BEA08741E0A6671BC | SHA256:5D706D4975D8ECD3E030C4AE647DDF9514F38F92448DF97B02DABF620576A950 | |||
| 2648 | csc.exe | C:\Users\admin\Desktop\CSC81893520984344A7ADAF93F13BE8BE64.TMP | binary | |
MD5:1B5017CF6386C7FEF34F14D49F8B042E | SHA256:42C0B53B11A21067C1FF924A83639B97ED7DEC8650B7AA6A2397DC68FE9BB961 | |||
| 1572 | svchost.exe | C:\Users\admin\Contacts\read_it.txt | text | |
MD5:4217B8B83CE3C3F70029A056546F8FD0 | SHA256:7D767E907BE373C680D1F7884D779588EB643BEBB3F27BF3B5ED4864AA4D8121 | |||
| 1572 | svchost.exe | C:\Users\admin\Documents\OneNote Notebooks\Personal\read_it.txt | text | |
MD5:4217B8B83CE3C3F70029A056546F8FD0 | SHA256:7D767E907BE373C680D1F7884D779588EB643BEBB3F27BF3B5ED4864AA4D8121 | |||
| 1572 | svchost.exe | C:\Users\admin\Documents\PowerShell\Modules\PSSQLite\1.1.0\read_it.txt | text | |
MD5:4217B8B83CE3C3F70029A056546F8FD0 | SHA256:7D767E907BE373C680D1F7884D779588EB643BEBB3F27BF3B5ED4864AA4D8121 | |||
| 1572 | svchost.exe | C:\Users\admin\Downloads\read_it.txt | text | |
MD5:4217B8B83CE3C3F70029A056546F8FD0 | SHA256:7D767E907BE373C680D1F7884D779588EB643BEBB3F27BF3B5ED4864AA4D8121 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |