VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
Windows Exe (x86-32)
Created at 2019-05-06T19:42:00
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sihvgt.exe | Sample File | Binary |
File Reputation Information
Severity |
First Seen | 2019-05-06 13:11 (UTC+2) |
Last Seen | 2019-05-06 13:18 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
Image Base | 0x400000 |
Entry Point | 0x40a224 |
Size Of Initialized Data | 0xc800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-10 02:47:20+00:00 |
Sections (1)
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
.rdata | 0x401000 | 0xda15 | 0xdc00 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_WRITE | 6.03 |
Imports (7)
KERNEL32.dll (50)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
Process32NextW | 0x0 | 0x401024 | 0xd160 | 0xc360 | 0x398 |
HeapReAlloc | 0x0 | 0x401028 | 0xd164 | 0xc364 | 0x2d2 |
HeapFree | 0x0 | 0x40102c | 0xd168 | 0xc368 | 0x2cf |
GetProcessHeap | 0x0 | 0x401030 | 0xd16c | 0xc36c | 0x24a |
lstrlenA | 0x0 | 0x401034 | 0xd170 | 0xc370 | 0x54d |
GetLastError | 0x0 | 0x401038 | 0xd174 | 0xc374 | 0x202 |
GetFileSizeEx | 0x0 | 0x40103c | 0xd178 | 0xc378 | 0x1f1 |
WriteFile | 0x0 | 0x401040 | 0xd17c | 0xc37c | 0x525 |
ReadFile | 0x0 | 0x401044 | 0xd180 | 0xc380 | 0x3c0 |
SetFilePointerEx | 0x0 | 0x401048 | 0xd184 | 0xc384 | 0x467 |
CreateFileW | 0x0 | 0x40104c | 0xd188 | 0xc388 | 0x8f |
GetCurrentProcess | 0x0 | 0x401050 | 0xd18c | 0xc38c | 0x1c0 |
ExitProcess | 0x0 | 0x401054 | 0xd190 | 0xc390 | 0x119 |
CreateThread | 0x0 | 0x401058 | 0xd194 | 0xc394 | 0xb5 |
GetCurrentThread | 0x0 | 0x40105c | 0xd198 | 0xc398 | 0x1c4 |
SetThreadPriority | 0x0 | 0x401060 | 0xd19c | 0xc39c | 0x499 |
WaitForMultipleObjects | 0x0 | 0x401064 | 0xd1a0 | 0xc3a0 | 0x4f7 |
Sleep | 0x0 | 0x401068 | 0xd1a4 | 0xc3a4 | 0x4b2 |
GetLogicalDrives | 0x0 | 0x40106c | 0xd1a8 | 0xc3a8 | 0x209 |
GetStdHandle | 0x0 | 0x401070 | 0xd1ac | 0xc3ac | 0x264 |
Process32FirstW | 0x0 | 0x401074 | 0xd1b0 | 0xc3b0 | 0x396 |
FindClose | 0x0 | 0x401078 | 0xd1b4 | 0xc3b4 | 0x12e |
lstrcmpiA | 0x0 | 0x40107c | 0xd1b8 | 0xc3b8 | 0x544 |
lstrcmpiW | 0x0 | 0x401080 | 0xd1bc | 0xc3bc | 0x545 |
lstrcpyW | 0x0 | 0x401084 | 0xd1c0 | 0xc3c0 | 0x548 |
lstrcatW | 0x0 | 0x401088 | 0xd1c4 | 0xc3c4 | 0x53f |
GetModuleFileNameW | 0x0 | 0x40108c | 0xd1c8 | 0xc3c8 | 0x214 |
CreateProcessW | 0x0 | 0x401090 | 0xd1cc | 0xc3cc | 0xa8 |
GetEnvironmentVariableW | 0x0 | 0x401094 | 0xd1d0 | 0xc3d0 | 0x1dc |
GetDriveTypeA | 0x0 | 0x401098 | 0xd1d4 | 0xc3d4 | 0x1d2 |
GetTempFileNameW | 0x0 | 0x40109c | 0xd1d8 | 0xc3d8 | 0x283 |
SetFileAttributesW | 0x0 | 0x4010a0 | 0xd1dc | 0xc3dc | 0x461 |
GetFileAttributesW | 0x0 | 0x4010a4 | 0xd1e0 | 0xc3e0 | 0x1ea |
FindFirstFileW | 0x0 | 0x4010a8 | 0xd1e4 | 0xc3e4 | 0x139 |
FindNextFileW | 0x0 | 0x4010ac | 0xd1e8 | 0xc3e8 | 0x145 |
CopyFileW | 0x0 | 0x4010b0 | 0xd1ec | 0xc3ec | 0x75 |
MoveFileExW | 0x0 | 0x4010b4 | 0xd1f0 | 0xc3f0 | 0x360 |
SetPriorityClass | 0x0 | 0x4010b8 | 0xd1f4 | 0xc3f4 | 0x47d |
MultiByteToWideChar | 0x0 | 0x4010bc | 0xd1f8 | 0xc3f8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4010c0 | 0xd1fc | 0xc3fc | 0x511 |
CompareStringA | 0x0 | 0x4010c4 | 0xd200 | 0xc400 | 0x61 |
CreateToolhelp32Snapshot | 0x0 | 0x4010c8 | 0xd204 | 0xc404 | 0xbe |
CreateProcessA | 0x0 | 0x4010cc | 0xd208 | 0xc408 | 0xa4 |
lstrlenW | 0x0 | 0x4010d0 | 0xd20c | 0xc40c | 0x54e |
lstrcatA | 0x0 | 0x4010d4 | 0xd210 | 0xc410 | 0x53e |
lstrcpyA | 0x0 | 0x4010d8 | 0xd214 | 0xc414 | 0x547 |
CloseHandle | 0x0 | 0x4010dc | 0xd218 | 0xc418 | 0x52 |
HeapAlloc | 0x0 | 0x4010e0 | 0xd21c | 0xc41c | 0x2cb |
SetFilePointer | 0x0 | 0x4010e4 | 0xd220 | 0xc420 | 0x466 |
HeapCreate | 0x0 | 0x4010e8 | 0xd224 | 0xc424 | 0x2cd |
USER32.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
wsprintfA | 0x0 | 0x401118 | 0xd254 | 0xc454 | 0x332 |
ADVAPI32.dll (8)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
RegQueryValueExW | 0x0 | 0x401000 | 0xd13c | 0xc33c | 0x26e |
RegCreateKeyExW | 0x0 | 0x401004 | 0xd140 | 0xc340 | 0x239 |
RegCloseKey | 0x0 | 0x401008 | 0xd144 | 0xc344 | 0x230 |
CryptGenRandom | 0x0 | 0x40100c | 0xd148 | 0xc348 | 0xc1 |
CryptReleaseContext | 0x0 | 0x401010 | 0xd14c | 0xc34c | 0xcb |
CryptAcquireContextW | 0x0 | 0x401014 | 0xd150 | 0xc350 | 0xb1 |
RegSetValueExW | 0x0 | 0x401018 | 0xd154 | 0xc354 | 0x27e |
RegOpenKeyExW | 0x0 | 0x40101c | 0xd158 | 0xc358 | 0x261 |
SHELL32.dll (2)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
SHChangeNotify | 0x0 | 0x4010f8 | 0xd234 | 0xc434 | 0x7f |
ShellExecuteExW | 0x0 | 0x4010fc | 0xd238 | 0xc438 | 0x121 |
SHLWAPI.dll (4)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
StrStrA | 0x0 | 0x401104 | 0xd240 | 0xc440 | 0x143 |
PathAddBackslashW | 0x0 | 0x401108 | 0xd244 | 0xc444 | 0x30 |
PathFindFileNameW | 0x0 | 0x40110c | 0xd248 | 0xc448 | 0x49 |
PathRemoveFileSpecW | 0x0 | 0x401110 | 0xd24c | 0xc44c | 0x8b |
ntdll.dll (4)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
_chkstk | 0x0 | 0x401120 | 0xd25c | 0xc45c | 0x502 |
_allrem | 0x0 | 0x401124 | 0xd260 | 0xc460 | 0x4fa |
_alldiv | 0x0 | 0x401128 | 0xd264 | 0xc464 | 0x4f6 |
_aulldiv | 0x0 | 0x40112c | 0xd268 | 0xc468 | 0x4fe |
RPCRT4.dll (1)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
UuidCreate | 0x0 | 0x4010f0 | 0xd22c | 0xc42c | 0x1fb |
Memory Dumps (2)
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
sihvgt.exe | 1 | 0x00400000 | 0x0040EFFF | Content Changed | - | 32-bit | 0x00409F1B, 0x0040A224 |
![]() |
![]() |
sihvgt.exe | 1 | 0x00400000 | 0x0040EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
Local AV Matches (1)
Threat Name | Severity |
Generic.Ransom.GlobeImposter.EAEF7CF9 |
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg | Modified File | Stream |
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg | Modified File | Stream |
C:\Users\Public\Music\Sample Music\desktop.ini | Modified File | Stream |
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3 | Modified File | Stream |
C:\Users\Public\Desktop\Mozilla Firefox.lnk | Modified File | Stream |
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
C:\Users\Default\Searches\Everywhere.search-ms | Modified File | Stream |
C:\Users\Default\Saved Games\desktop.ini | Modified File | Stream |
C:\Users\Default\Music\desktop.ini | Modified File | Stream |
C:\Users\Default\Links\desktop.ini | Modified File | Stream |
C:\Users\Default\Links\Desktop.lnk | Modified File | Stream |
C:\Users\Default\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
C:\Users\Default\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
C:\Users\Default\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
C:\Users\Default\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
C:\Users\Default\Contacts\desktop.ini | Modified File | Stream |
C:\Users\Default\AppData\Local\IconCache.db | Modified File | Stream |
C:\Users\Public\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Videos\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Videos\Sample Videos\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv | Modified File | Stream |
Not Queried
C:\Users\Public\Recorded TV\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Recorded TV\Sample Media\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg | Modified File | Stream |
Not Queried
C:\Users\Public\Music\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Music\Sample Music\Kalimba.mp3 | Modified File | Stream |
Not Queried
C:\Users\Public\Music\Sample Music\Sleep Away.mp3 | Modified File | Stream |
Not Queried
C:\Users\Public\Libraries\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Not Queried
C:\Users\Public\Downloads\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Documents\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Desktop\Adobe Reader X.lnk | Modified File | Stream |
Not Queried
C:\Users\Public\Desktop\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Public\Desktop\Google Chrome.lnk | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT.LOG | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT.LOG1 | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf | Modified File | Stream |
Not Queried
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Not Queried
C:\Users\Default\ntuser.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Videos\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Searches\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Searches\Indexed Locations.search-ms | Modified File | Stream |
Not Queried
C:\Users\Default\Pictures\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Links\Downloads.lnk | Modified File | Stream |
Not Queried
C:\Users\Default\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
C:\Users\Default\Favorites\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
C:\Users\Default\Favorites\Links\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Not Queried
C:\Users\Default\Downloads\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Documents\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Desktop\desktop.ini | Modified File | Stream |
Not Queried
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
C:\Users\Default\AppData\Local\Temp\FXSAPIDebugLogFile.txt | Modified File | Stream |
Not Queried
C:\Users\All Users\Sun\Java\Java Update\jaureglist.xml.{Killback@protonmail.com}KBK | Modified File | Stream |
Not Queried
C:\Users\Public\93603CF02EAF23F319BB1EF860A69BA06C8E84CE34898E7A109832B06CDDB887 | Dropped File | Text |
Not Queried