Created 1 year ago
Setup.exe
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 minutes" to "20 seconds" to reveal dormant functionality.
VMRay Threat Identifiers (14 rules, 21 matches)
Score | Category | Operation | Count | Classification | |
---|---|---|---|---|---|
5/5 | User Data Modification | Appends new extensions to many filenames | 1 | Ransomware | |
5/5 | User Data Modification | Encrypts content of user files | 1 | Ransomware | |
4/5 | Defense Evasion | Bypasses Windows User Account Control (UAC) | 1 | - | |
4/5 | Reputation | Malicious file detected via reputation | 3 | - | |
3/5 | System Modification | Modifies system configuration | 1 | - | |
2/5 | System Modification | Changes the desktop wallpaper | 1 | - | |
2/5 | Hide Tracks | Hides files | 4 | - | |
1/5 | Privilege Escalation | Enables process privileges | 1 | - | |
1/5 | Input Capture | Monitors mouse movements and clicks | 1 | - | |
1/5 | Defense Evasion | Accesses volumes directly | 1 | - | |
Screenshots
MITRE ATT&CK™ Matrix - Windows
Sample Information
ID | #9566692 |
MD5 | |
SHA1 | |
SHA256 | |
SSDeep | |
ImpHash | |
File Name | Setup.exe |
File Size | 12548.00 KB |
Sample Type | Windows Exe (x86-32) |
Analysis Information
Creation Time | 2023-12-27 00:12 (UTC+) |
Analysis Duration | 00:04:00 |
Termination Reason | Timeout |
Number of Monitored Processes | 32 |
Execution Successful | |
Reputation Enabled | |
Built-in AV Enabled | |
Number of AV Matches | 0 |
YARA Enabled | |
Number of YARA Matches | 0 |