VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Trojan.GenericKD.42890724
Mal/Generic-S
|
bild.exe
Windows Exe (x86-32)
Created 5 years ago
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bild.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x457840 |
Size Of Code | 0x11d200 |
Size Of Initialized Data | 0x16000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11d0be | 0x11d200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.11 |
.rdata | 0x51f000 | 0x1327f7 | 0x132800 | 0x11d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.73 |
.data | 0x652000 | 0x2ac18 | 0x16000 | 0x24fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.08 |
.idata | 0x67d000 | 0x3aa | 0x400 | 0x265e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.53 |
.symtab | 0x67e000 | 0x4 | 0x200 | 0x266200 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
kernel32.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x652020 | 0x27d312 | 0x266112 | 0x0 |
WriteConsoleW | 0x0 | 0x652024 | 0x27d316 | 0x266116 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x652028 | 0x27d31a | 0x26611a | 0x0 |
WaitForSingleObject | 0x0 | 0x65202c | 0x27d31e | 0x26611e | 0x0 |
VirtualQuery | 0x0 | 0x652030 | 0x27d322 | 0x266122 | 0x0 |
VirtualFree | 0x0 | 0x652034 | 0x27d326 | 0x266126 | 0x0 |
VirtualAlloc | 0x0 | 0x652038 | 0x27d32a | 0x26612a | 0x0 |
SwitchToThread | 0x0 | 0x65203c | 0x27d32e | 0x26612e | 0x0 |
SuspendThread | 0x0 | 0x652040 | 0x27d332 | 0x266132 | 0x0 |
SetWaitableTimer | 0x0 | 0x652044 | 0x27d336 | 0x266136 | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x652048 | 0x27d33a | 0x26613a | 0x0 |
SetProcessPriorityBoost | 0x0 | 0x65204c | 0x27d33e | 0x26613e | 0x0 |
SetEvent | 0x0 | 0x652050 | 0x27d342 | 0x266142 | 0x0 |
SetErrorMode | 0x0 | 0x652054 | 0x27d346 | 0x266146 | 0x0 |
SetConsoleCtrlHandler | 0x0 | 0x652058 | 0x27d34a | 0x26614a | 0x0 |
ResumeThread | 0x0 | 0x65205c | 0x27d34e | 0x26614e | 0x0 |
PostQueuedCompletionStatus | 0x0 | 0x652060 | 0x27d352 | 0x266152 | 0x0 |
LoadLibraryA | 0x0 | 0x652064 | 0x27d356 | 0x266156 | 0x0 |
LoadLibraryW | 0x0 | 0x652068 | 0x27d35a | 0x26615a | 0x0 |
SetThreadContext | 0x0 | 0x65206c | 0x27d35e | 0x26615e | 0x0 |
GetThreadContext | 0x0 | 0x652070 | 0x27d362 | 0x266162 | 0x0 |
GetSystemInfo | 0x0 | 0x652074 | 0x27d366 | 0x266166 | 0x0 |
GetSystemDirectoryA | 0x0 | 0x652078 | 0x27d36a | 0x26616a | 0x0 |
GetStdHandle | 0x0 | 0x65207c | 0x27d36e | 0x26616e | 0x0 |
GetQueuedCompletionStatus | 0x0 | 0x652080 | 0x27d372 | 0x266172 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x652084 | 0x27d376 | 0x266176 | 0x0 |
GetProcAddress | 0x0 | 0x652088 | 0x27d37a | 0x26617a | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x65208c | 0x27d37e | 0x26617e | 0x0 |
GetConsoleMode | 0x0 | 0x652090 | 0x27d382 | 0x266182 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x652094 | 0x27d386 | 0x266186 | 0x0 |
ExitProcess | 0x0 | 0x652098 | 0x27d38a | 0x26618a | 0x0 |
DuplicateHandle | 0x0 | 0x65209c | 0x27d38e | 0x26618e | 0x0 |
CreateThread | 0x0 | 0x6520a0 | 0x27d392 | 0x266192 | 0x0 |
CreateIoCompletionPort | 0x0 | 0x6520a4 | 0x27d396 | 0x266196 | 0x0 |
CreateEventA | 0x0 | 0x6520a8 | 0x27d39a | 0x26619a | 0x0 |
CloseHandle | 0x0 | 0x6520ac | 0x27d39e | 0x26619e | 0x0 |
AddVectoredExceptionHandler | 0x0 | 0x6520b0 | 0x27d3a2 | 0x2661a2 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bild.exe | 1 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0042A09A |
![]() |
![]() |
...
|
bild.exe | 1 | 0x00400000 | 0x0067EFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42890724 |
Malicious
|
File Reputation Information
»
Severity |
Whitelisted
|
File Reputation Information
»
Severity |
Whitelisted
|
./\9GRFd/OHfszhgPx4PUujetED6W.m4a | Modified File | Stream |
Whitelisted
|
...
|
»
./\b _CgEc/foqU phhuF5whaIL14.swf | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
File Reputation Information
»
Severity |
Whitelisted
|
File Reputation Information
»
Severity |
Whitelisted
|
File Reputation Information
»
Severity |
Whitelisted
|
C:\/BOOTSECT.BAK_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//--E6t.mkv_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//3dL-1RFivlm.wav_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//2DM2GvIwVx-v.jpg_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//Bg9_AOEKKkspKLd5.mp4_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//fKBAZ-9WEL.png_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//eIcvG1cH.mkv_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//imC7z3eV_GUgNvTJTX.flv_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//iq85Nxk_wOWWvm.m4a_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//kAQ8mk.png_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//OIm8YuGFZVf2MO.m4a_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//pMAWe0dsYEySTQi.mp3_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//RAtpNkfHaeqiM9JU_.png_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//WiTiydOI7bp 4LSZ.avi_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//zP1iS.pptx_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//Zqp1QIxb.jpg_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//_s7S5x2XTq7Xj8KCfw.odt_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files/desktop.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)/desktop.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users/desktop.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\dtcinstall.log_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/fveupdate.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/msdfmap.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\pfro.log_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/notepad.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/setupact.log_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/Starter.xml_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/system.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/splwow64.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/TSSysprep.log_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/twain.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/vbaddin.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/win.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/WindowsShell.Manifest_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\b _CgEc/EEic7BtX.mkv_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\b _CgEc/foqU phhuF5whaIL14.swf_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\b _CgEc/pReqV.bmp_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\hVnRgUQL/guTseBtUMsArX.mp3_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\desktop\hvnrguql\d-6ifxl.flv_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000/desktop.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\boot\cs-cz\bootmgr.exe.mui_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\boot\fi-fi\bootmgr.exe.mui_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\de-DE/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\hu-HU/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\en-US/memtest.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ko-KR/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pt-PT/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files/foxmailincmail.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\dvd maker\bod_r.ttf_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker/Eurosti.TTF_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\dvd maker\fe_occurring.exe_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/ieinstal.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/ielowutil.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/ieproxy.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/JSProfilerCore.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/jsprofilerui.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\internet explorer\msdbg2.dll_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/notepad.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\icq.exe_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Sync Framework/sectionanyoneordering.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nl-NL/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\msbuild\scriptftp.exe_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ru-RU/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\tr-TR/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Defender/MpAsDesc.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Defender/MpCommu.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\windows defender\mpsvc.dll_id_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Journal/jnwdui.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Journal/jnwppr.dll_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Sidebar/settings.ini_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Internet Explorer/ieinstal.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Internet Explorer/ielowutil.exe_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\da-DK/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\el-GR/bootmgr.exe.mui_ID_2620738370_doss_help@qq.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot/BCD.LOG_ID_2620738370_doss_help@qq.com.google | Dropped File | Unknown |
Not Queried
|
...
|
»