🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d33ac8fce0592ef88bdeeee00e840c41a5a8fccc85c67316b74cc06c13ba0c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Conti


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 2d33ac8fce0592ef88bdeeee00e840c41a5a8fccc85c67316b74cc06c13ba0c5
SHA3-384 hash: 1c4376dbd44324d16759be0c047a25e56e584f44cf131819fd6783bb453de0fa4edc642b86c976da8e122890574b5190
SHA1 hash: 2fd36e604ef5f11ded128c6edcbb4c1ee5f7a91f
MD5 hash: 72acae41645beae9afeef212b9e56be9
humanhash: minnesota-happy-september-florida
File name:2d33ac8fce0592ef88bdeeee00e840c41a5a8fccc85c67316b74cc06c13ba0c5
Download: download sample
Signature Conti
File size:222'208 bytes
First seen:2022-03-02 11:07:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 137fa89046164fe07e0dd776ed7a0191 (7 x Conti)
ssdeep 3072:a6ZPkBIwEgmmX9WJ3yubwvmEuAvBRTWqSYTE2lIlMrSMLBhMs7/C26:akoItgmq9WJ3yuUeEr7TGz2liMGW9t6
Threatray 14 similar samples on MalwareBazaar
TLSH T1CF24F740B16EDBE9D1D383B88956A602BEF735C02B549EEBC3864A710D070D572EDFA1
Reporter vxunderground
Tags:conti exe Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
632
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file
Changing a file
Creating a file in the Program Files directory
Moving a file to the Program Files directory
Creating a file in the Program Files subdirectories
Moving a file to the Program Files subdirectory
Moving a recently created file
Modifying an executable file
Reading critical registry keys
Creating a file in the mass storage device
Stealing user critical data
Encrypting user's files
Forced shutdown of a browser
Infecting executable files
Result
Malware family:
n/a
Score:
  0/10
Tags:
n/a
Behaviour
CheckCmdLine
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
expand.exe greyware
Result
Threat name:
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many different private IPs (likely to spread or exploit)
Found ransom note / readme
Found Tor onion address
Infects executable files (exe, dll, sys, html)
Multi AV Scanner detection for submitted file
Sigma detected: Regsvr32 Network Activity
Sigma detected: Suspicious Call by Ordinal
System process connects to network (likely due to code injection or exploit)
Writes many files with high entropy
Yara detected Conti ransomware
Behaviour
Behavior Graph:
Threat name:
Win64.Ransomware.Conti
Status:
Malicious
First seen:
2022-03-02 02:36:00 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
26 of 43 (60.47%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:conti ransomware
Behaviour
Suspicious behavior: EnumeratesProcesses
Drops file in Program Files directory
Drops desktop.ini file(s)
Modifies extensions of user files
Conti Ransomware
Unpacked files
SH256 hash:
2d33ac8fce0592ef88bdeeee00e840c41a5a8fccc85c67316b74cc06c13ba0c5
MD5 hash:
72acae41645beae9afeef212b9e56be9
SHA1 hash:
2fd36e604ef5f11ded128c6edcbb4c1ee5f7a91f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_conti_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.conti.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments