VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
1.exe
Windows Exe (x86-32)
Created at 2019-12-07T18:06:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-12-07 14:35 (UTC+1) |
Last Seen | 2019-12-07 15:57 (UTC+1) |
Names | Win32.Trojan.Heur2 |
Families | Heur2 |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x663a90 |
Size Of Code | 0x97000 |
Size Of Initialized Data | 0x10000 |
Size Of Uninitialized Data | 0x1cc000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-07 12:09:20+00:00 |
Version Information (5)
»
FileDescription | Project |
FileVersion | 1.0.0.0 |
ProductName | Project |
ProductVersion | 1.0.0.0 |
ProgramID | com.embarcadero.Project |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x1cc000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x5cd000 | 0x97000 | 0x96e00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x664000 | 0x10000 | 0xf400 | 0x97200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.4 |
Imports (11)
»
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x67324c | 0x27324c | 0xa644c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Add | 0x0 | 0x673254 | 0x273254 | 0xa6454 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0x67325c | 0x27325c | 0xa645c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x673264 | 0x273264 | 0xa6464 | 0x0 |
ExitProcess | 0x0 | 0x673268 | 0x273268 | 0xa6468 | 0x0 |
GetProcAddress | 0x0 | 0x67326c | 0x27326c | 0xa646c | 0x0 |
VirtualProtect | 0x0 | 0x673270 | 0x273270 | 0xa6470 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x673278 | 0x273278 | 0xa6478 | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0x673280 | 0x273280 | 0xa6480 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantInit | 0x0 | 0x673288 | 0x273288 | 0xa6488 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Shell_NotifyIconW | 0x0 | 0x673290 | 0x273290 | 0xa6490 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x673298 | 0x273298 | 0xa6498 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x6732a0 | 0x2732a0 | 0xa64a0 | 0x0 |
winspool.drv (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClosePrinter | 0x0 | 0x6732a8 | 0x2732a8 | 0xa64a8 | 0x0 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
1.exe | 1 | 0x00400000 | 0x00673FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00700000 | 0x00700FFF | First Execution | - | 32-bit | 0x00700FE2 |
![]() |
![]() |
...
|
buffer | 1 | 0x00700000 | 0x00700FFF | Content Changed | - | 32-bit | 0x00700FC8 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur2.LPTPmKfbWjX0Diib |
Malicious
|
C:\Users\FD1HVy\Desktop\-U-3BfnT-lcAhaa8ktXt.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6sj8bBaZY8kNwyyBJm.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\92RGc2UxVrSXFXglHvuI.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\eJ6l3qghM649uhdfa2Dr.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ewClrNa_-BFg3aZFusX.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\exq_flWIablfJcXB.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HXAy7RmTrlZkk.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\j6NYSFPqn-dwdKTZAtm.doc.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oegKhonc.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\q6uXH48hD2SkJOYforn.doc.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Sma3wNlUeCXl354oD5.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\x_xBLfTRf95bwE\JwtWO7W-utEnlU2.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\x_xBLfTRf95bwE\s5CY0mf.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\Kfy95qj 8zmSj4wmBZm.doc.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\u41dItxWLoq.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\pY98x-2\1enPcpg3n5qltwm_J.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\pY98x-2\TenrrjVKw4G0z.rtf.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\TBX76po0YT0\AergoMWc3.rtf.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\TBX76po0YT0\Q-s_4C5AyKat8.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\TBX76po0YT0\z9_8u.rtf.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AkKl58uxJF\k90FqMe-OViAp\VTMYTwfv_qX_qX1Y-Kz\Nl7w\PO0wd\11PcchD\srEwx0N3g8QTXQyfP6eP.rtf.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Nb4IeC\iO2PqHizd5dRXIH-Pbe-.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Nb4IeC\_iobQdS.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0LdIDlJ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0tre.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5RnA7.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7lD2i7M.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bpx0d.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\EhR4AiA.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F7LEp5iBo_rTQNDL.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HW6wB goRmI6wDLHy.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\kVVpgrJzI.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\MQGfkZadO059eMsq1Z.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\MX1aTsKU26Md9uyI_ON.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Nf8-LcBADQBdVO.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NWeO.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oJRbqsa3dPk3xiesxlw.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oPqMpGpNZj5zVL.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\RIxmXOX.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\s_FNC8pL5AdcZmo.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\VL0Y5.jpg.MaMo434376 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\yzfd2.png.MaMo434376 | Dropped File | Binary |
Unknown
|
...
|
»