🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea524e8b0dd046561b59a8d4da5a122aeff02036c87bb03056437a1d0f584039. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Conti


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: ea524e8b0dd046561b59a8d4da5a122aeff02036c87bb03056437a1d0f584039
SHA3-384 hash: 704573be0a6f31cfb3884a3f04c3c55f2bb351c8bdb5b94089214e7830f533e509d4f4ad217c15c91f8aefd85c26d8bd
SHA1 hash: aceaa5ab418ea94d2bc16f3584024ab55b9afb7e
MD5 hash: 37cb63ecf10bed57f238691279d25d6c
humanhash: pizza-massachusetts-edward-helium
File name:ea524e8b0dd046561b59a8d4da5a122aeff02036c87bb03056437a1d0f584039.bin
Download: download sample
Signature Conti
File size:220'672 bytes
First seen:2022-02-25 23:02:04 UTC
Last seen:2022-02-26 07:35:44 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 137fa89046164fe07e0dd776ed7a0191 (7 x Conti)
ssdeep 3072:zTF7B9rkmgFhO3lGX5eKpTZTVBr1+6fqdNdfu6BeixpMVjMWCg/Cm1t:FHrngLgGXwKpTZ9/wfuQe6pgPr
Threatray 7 similar samples on MalwareBazaar
TLSH T168241901B11ECBAAD99343BD8997A602FDF7358027148EEB83844A705D0F2D576EDFA1
Reporter Arkbird_SOLG
Tags:conti exe Ransomware

Intelligence


File Origin
# of uploads :
2
# of downloads :
648
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file
Changing a file
Creating a file in the Program Files directory
Moving a file to the Program Files directory
Creating a file in the Program Files subdirectories
Moving a file to the Program Files subdirectory
Modifying an executable file
Moving a recently created file
Sending a custom TCP request
Reading critical registry keys
Creating a file in the mass storage device
Stealing user critical data
Encrypting user's files
Forced shutdown of a browser
Infecting executable files
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
MalwareBazaar
MeasuringTime
CheckCmdLine
EvasionQueryPerformanceCounter
Result
Threat name:
Detection:
malicious
Classification:
rans.spre.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Connects to many different private IPs (likely to spread or exploit)
Found ransom note / readme
Found Tor onion address
Infects executable files (exe, dll, sys, html)
Multi AV Scanner detection for submitted file
Sigma detected: Regsvr32 Network Activity
Sigma detected: Suspicious Call by Ordinal
System process connects to network (likely due to code injection or exploit)
Writes many files with high entropy
Yara detected Conti ransomware
Behaviour
Behavior Graph:
Threat name:
Win64.Ransomware.Conti
Status:
Malicious
First seen:
2021-11-30 02:46:27 UTC
File Type:
PE+ (Dll)
Extracted files:
1
AV detection:
30 of 43 (69.77%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:conti ransomware
Behaviour
Suspicious behavior: EnumeratesProcesses
Drops file in Program Files directory
Drops desktop.ini file(s)
Drops startup file
Modifies extensions of user files
Conti Ransomware
Unpacked files
SH256 hash:
ea524e8b0dd046561b59a8d4da5a122aeff02036c87bb03056437a1d0f584039
MD5 hash:
37cb63ecf10bed57f238691279d25d6c
SHA1 hash:
aceaa5ab418ea94d2bc16f3584024ab55b9afb7e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments