General
-
Target
installer.exe
-
Size
23KB
-
Sample
250511-e2hsysvxev
-
MD5
06922caf5b678158a2e6fe89301c5f5c
-
SHA1
aec21e9dcf48aea56c573b330edc494f58180e1e
-
SHA256
06fd7069b75bf765c802f1f24d40c44ad52717652c3bc708c0805e39526f90bf
-
SHA512
f58ca0b5e4153156b1f89c975fa412eba2e453948bb6eb096c8702eb24acb5aac0d7a4691bcf90ea262fd0b3f59d811b9548dabcd339ab057c85846be1c12058
-
SSDEEP
384:2A3Mg/bqo2sDOcUiU5p7Ut3LTAzkcJtr91CHbGhZCezI:2+qo2zhrp7abTz0tr9mGh4ezI
Behavioral task
behavioral1
Sample
installer.exe
Resource
win10v2004-20250502-es
Behavioral task
behavioral2
Sample
installer.exe
Resource
win11-20250502-es
Malware Config
Extracted
C:\Users\Admin\Documents\read_it.txt
chaos
https://discord.gg/XX4wkFbw
Targets
-
-
Target
installer.exe
-
Size
23KB
-
MD5
06922caf5b678158a2e6fe89301c5f5c
-
SHA1
aec21e9dcf48aea56c573b330edc494f58180e1e
-
SHA256
06fd7069b75bf765c802f1f24d40c44ad52717652c3bc708c0805e39526f90bf
-
SHA512
f58ca0b5e4153156b1f89c975fa412eba2e453948bb6eb096c8702eb24acb5aac0d7a4691bcf90ea262fd0b3f59d811b9548dabcd339ab057c85846be1c12058
-
SSDEEP
384:2A3Mg/bqo2sDOcUiU5p7Ut3LTAzkcJtr91CHbGhZCezI:2+qo2zhrp7abTz0tr9mGh4ezI
-
Chaos Ransomware
-
Chaos family
-
Deletes shadow copies
Ransomware often targets backup files to inhibit system recovery.
-
Modifies boot configuration data using bcdedit
-
Renames multiple (204) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Checks computer location settings
Looks up country code configured in the registry, likely geofence.
-
Drops startup file
-
Executes dropped EXE
-
Drops desktop.ini file(s)
-