🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf487bd54e487585cd052e982fd765cbc0d8d164cc21b8635e55475182dadf00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Conti


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: cf487bd54e487585cd052e982fd765cbc0d8d164cc21b8635e55475182dadf00
SHA3-384 hash: 5f1975f9d6b0f4cc8139f4313a24c66af5ffcd78247aa63cfb96cb7b219e764943ea51ffc40b5af0bb94f05a77e45401
SHA1 hash: 4313e5d451d60d66f6de4add392c1b9ff820f2f0
MD5 hash: fc589ff7ae38588841848235df247445
humanhash: three-cola-nine-nevada
File name:cf487bd54e487585cd052e982fd765cbc0d8d164cc21b8635e55475182dadf00.bin
Download: download sample
Signature Conti
File size:217'600 bytes
First seen:2022-02-25 23:01:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 66f2f8692fd4be171b9624da345bb20b (1 x Conti)
ssdeep 3072:r0DQ2Z3gE/uA5MoQ8gK31wu2VYaI4Yav8Aqe2OyEt8yE4FjMFNaWN:rHYgqgoQ8gK313Rr+yEWyGb
Threatray 8 similar samples on MalwareBazaar
TLSH T1A9241901B11EDBAAD9D343B88967AA02FDB6358027148EDB83844A705D0F3D576FDFA1
Reporter Arkbird_SOLG
Tags:conti exe Ransomware

Intelligence


File Origin
# of uploads :
1
# of downloads :
649
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file
Changing a file
Creating a file in the Program Files directory
Moving a file to the Program Files directory
Creating a file in the Program Files subdirectories
Moving a file to the Program Files subdirectory
Modifying an executable file
Moving a recently created file
Reading critical registry keys
Creating a file in the mass storage device
Stealing user critical data
Encrypting user's files
Forced shutdown of a browser
Infecting executable files
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
CheckCmdLine
EvasionQueryPerformanceCounter
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
conti filecoder mikey ransomware razy
Result
Threat name:
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
84 / 100
Signature
Connects to many different private IPs (likely to spread or exploit)
Found ransom note / readme
Infects executable files (exe, dll, sys, html)
Modifies existing user documents (likely ransomware behavior)
System process connects to network (likely due to code injection or exploit)
Tries to shutdown other security tools via broadcasted WM_QUERYENDSESSION
Writes many files with high entropy
Yara detected Conti ransomware
Behaviour
Behavior Graph:
Threat name:
Win64.Ransomware.Conti
Status:
Malicious
First seen:
2021-09-08 23:09:32 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
28 of 43 (65.12%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:conti ransomware
Behaviour
Suspicious behavior: EnumeratesProcesses
Drops file in Program Files directory
Drops desktop.ini file(s)
Drops startup file
Modifies extensions of user files
Conti Ransomware
Unpacked files
SH256 hash:
cf487bd54e487585cd052e982fd765cbc0d8d164cc21b8635e55475182dadf00
MD5 hash:
fc589ff7ae38588841848235df247445
SHA1 hash:
4313e5d451d60d66f6de4add392c1b9ff820f2f0
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments