Creation Time | 2016-09-26 12:41 (UTC+2) |
VM Analysis Duration Time | 00:02:45 |
Execution Successful | |
Sample Filename | 249bebc650b7160cfeee41d08bc61dc220ecb740.malware.exe |
Command Line Parameters | |
Prescript | |
Number of Processes | 9 |
Termination Reason | Timeout |
Download | Function Logfile Generic Logfile PCAP STIX/CybOX |
VTI Score 75 / 100 | |
VTI Database Version | 2.2 |
VTI Rule Match Count | 23 |
VTI Rule Type | Default (PE, ...) |
The tags feature is only available in the fully licensed version of VMRay Analyzer. |
ID | PID | Monitor Reason | Image Name | Command Line | Origin ID |
---|---|---|---|---|---|
#1 | 0xc8c | Analysis Target | 249bebc650b7160cfeee41d08bc61dc220ecb740.malware.exe | "C:\Users\WI2yhmtI onvScY7Pe\Desktop\249bebc650b7160cfeee41d08bc61dc220ecb740.malware.exe" | |
#2 | 0xd78 | Child Process | xumiasww.exe | "C:\Users\WI2yhmtI onvScY7Pe\ayooEMEE\XuMIAsww.exe" | #1 |
#3 | 0xdb8 | Child Process | yoummieo.exe | "C:\ProgramData\VmYMsIgM\YOUMMIEo.exe" | #1 |
#4 | 0x4 | Created Daemon | System | #1 | |
#5 | 0xe00 | Created Daemon | xuaecwog.exe | C:\ProgramData\BAIEAAcU\xUAEcwog.exe | #1 |
#6 | 0xe38 | Child Process | cmd.exe | C:\Windows\system32\cmd.exe /c "C:\Users\WI2yhmtI onvScY7Pe\Desktop\249bebc650b7160cfeee41d08bc61dc220ecb740.malware" | #1 |
#7 | 0xe4c | Child Process | reg.exe | reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1 | #1 |
#9 | 0xe60 | Child Process | reg.exe | reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2 | #1 |
#10 | 0xe68 | Child Process | reg.exe | reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f | #1 |
ID | #609232 |
MD5 Hash Value | a66df34f40f1345861846918f4f8f56d |
SHA1 Hash Value | 249bebc650b7160cfeee41d08bc61dc220ecb740 |
SHA256 Hash Value | 91de42dda9985493ed08b1e6b7f5c3931135189a5455a3afb9bac8cc8d7c0870 |
Filename | 249bebc650b7160cfeee41d08bc61dc220ecb740.malware.exe |
File Size | 1.99 MB (2084864 bytes) |
File Type | Windows Exe (x86-32) |
Analyzer Version | 1.11.0 |
Analyzer Build Date | 2016-09-19 10:58 (UTC+2) |
VM Name | win10_64 |
VM Description | Windows 10 (64-bit) |
VM Architecture | x86 64-bit |
VM OS | Windows 10 |
VM Kernel Version | 10.0.10240.16384 (c68ee22f-dcf6-4778-95c5-4a862be16567) |