VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
fuicpj.exe
Windows Exe (x86-32)
Created at 2019-08-21T22:39:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fuicpj.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4086df |
Size Of Code | 0x2b800 |
Size Of Initialized Data | 0x2000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-19 04:34:25+00:00 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2b6fa | 0x2b800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.69 |
.data | 0x42d000 | 0x1e6c | 0x2000 | 0x2bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.03 |
Imports (6)
»
kernel32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x42ea44 | 0x2eb68 | 0x2d768 | 0x0 |
GetProcAddress | 0x0 | 0x42ea48 | 0x2eb6c | 0x2d76c | 0x0 |
GetVersion | 0x0 | 0x42ea4c | 0x2eb70 | 0x2d770 | 0x0 |
LoadLibraryA | 0x0 | 0x42ea50 | 0x2eb74 | 0x2d774 | 0x0 |
VirtualAlloc | 0x0 | 0x42ea54 | 0x2eb78 | 0x2d778 | 0x0 |
VirtualProtect | 0x0 | 0x42ea58 | 0x2eb7c | 0x2d77c | 0x0 |
ExitProcess | 0x0 | 0x42ea5c | 0x2eb80 | 0x2d780 | 0x0 |
lstrlenA | 0x0 | 0x42ea60 | 0x2eb84 | 0x2d784 | 0x0 |
lstrcatA | 0x0 | 0x42ea64 | 0x2eb88 | 0x2d788 | 0x0 |
WriteTapemark | 0x0 | 0x42ea68 | 0x2eb8c | 0x2d78c | 0x0 |
msimg32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DllInitialize | 0x0 | 0x42ea70 | 0x2eb94 | 0x2d794 | 0x0 |
AlphaBlend | 0x0 | 0x42ea74 | 0x2eb98 | 0x2d798 | 0x0 |
TransparentBlt | 0x0 | 0x42ea78 | 0x2eb9c | 0x2d79c | 0x0 |
imagehlp.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RemovePrivateCvSymbolic | 0x0 | 0x42ea34 | 0x2eb58 | 0x2d758 | 0x0 |
ImageGetCertificateHeader | 0x0 | 0x42ea38 | 0x2eb5c | 0x2d75c | 0x0 |
ReBaseImage | 0x0 | 0x42ea3c | 0x2eb60 | 0x2d760 | 0x0 |
winspool.drv (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StartDocDlgA | 0x0 | 0x42ea80 | 0x2eba4 | 0x2d7a4 | 0x0 |
DeleteFormW | 0x0 | 0x42ea84 | 0x2eba8 | 0x2d7a8 | 0x0 |
DeletePrinterIC | 0x0 | 0x42ea88 | 0x2ebac | 0x2d7ac | 0x0 |
DEVICEMODE | 0x0 | 0x42ea8c | 0x2ebb0 | 0x2d7b0 | 0x0 |
WaitForPrinterChange | 0x0 | 0x42ea90 | 0x2ebb4 | 0x2d7b4 | 0x0 |
advapi32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLocalManagedApplicationData | 0x0 | 0x42ea00 | 0x2eb24 | 0x2d724 | 0x0 |
RegSetValueExW | 0x0 | 0x42ea04 | 0x2eb28 | 0x2d728 | 0x0 |
SetTokenInformation | 0x0 | 0x42ea08 | 0x2eb2c | 0x2d72c | 0x0 |
ConvertSidToStringSidW | 0x0 | 0x42ea0c | 0x2eb30 | 0x2d730 | 0x0 |
SetSecurityDescriptorOwner | 0x0 | 0x42ea10 | 0x2eb34 | 0x2d734 | 0x0 |
comctl32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_AddIcon | 0x0 | 0x42ea18 | 0x2eb3c | 0x2d73c | 0x0 |
CreatePropertySheetPageA | 0x0 | 0x42ea1c | 0x2eb40 | 0x2d740 | 0x0 |
ImageList_DragLeave | 0x0 | 0x42ea20 | 0x2eb44 | 0x2d744 | 0x0 |
GetMUILanguage | 0x0 | 0x42ea24 | 0x2eb48 | 0x2d748 | 0x0 |
DPA_InsertPtr | 0x0 | 0x42ea28 | 0x2eb4c | 0x2d74c | 0x0 |
Str_SetPtrW | 0x0 | 0x42ea2c | 0x2eb50 | 0x2d750 | 0x0 |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
fuicpj.exe | 1 | 0x00400000 | 0x0042EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | First Execution | - | 32-bit | 0x00289BBB |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x0028A000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x0028B3DE |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x00283600 |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x00288568 |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x00286BC5 |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x00287000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00280000 | 0x002AEFFF | Content Changed | - | 32-bit | 0x00285000 |
![]() |
![]() |
...
|
fuicpj.exe | 1 | 0x00400000 | 0x0042EFFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.41613105 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.msi.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.nemty | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer\SIGNUP\install.ins.nemty | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\5p5nrgjn0js_halpmcxz@db-ip[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\DVD Maker\Shared\DvdStyles\Shatter\NEMTY-DECRYPT.txt | Dropped File | Text |
Unknown
|
...
|
»