VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Ransomware
|
Threat Names: |
Satana
Mal/Generic-S
|
file2.exe
Windows Exe (x86-32)
Created at 2020-03-12T03:05:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "11 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
0 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4052c0 |
Size Of Code | 0x5000 |
Size Of Initialized Data | 0x14600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 13:02:39+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x4f30 | 0x5000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.44 |
.rdata | 0x406000 | 0x283e | 0x2a00 | 0x5400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.27 |
.data | 0x409000 | 0x10b8c | 0x1e00 | 0x7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.9 |
.CRT | 0x41a000 | 0x8 | 0x200 | 0x9c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.tls | 0x41b000 | 0xc | 0x200 | 0x9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.reloc | 0x41c000 | 0xaba | 0xc00 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.67 |
Imports (2)
»
ntdll.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlInitializeCriticalSection | 0x0 | 0x406110 | 0x816c | 0x756c | 0x273 |
wcstombs | 0x0 | 0x406114 | 0x8170 | 0x7570 | 0x580 |
wcsncmp | 0x0 | 0x406118 | 0x8174 | 0x7574 | 0x579 |
NtOpenProcess | 0x0 | 0x40611c | 0x8178 | 0x7578 | 0xc7 |
strrchr | 0x0 | 0x406120 | 0x817c | 0x757c | 0x564 |
RtlGetNtVersionNumbers | 0x0 | 0x406124 | 0x8180 | 0x7580 | 0x259 |
CsrGetProcessId | 0x0 | 0x406128 | 0x8184 | 0x7584 | 0x9 |
NtDelayExecution | 0x0 | 0x40612c | 0x8188 | 0x7588 | 0x87 |
wcsstr | 0x0 | 0x406130 | 0x818c | 0x758c | 0x57e |
wcsrchr | 0x0 | 0x406134 | 0x8190 | 0x7590 | 0x57c |
NtSetInformationThread | 0x0 | 0x406138 | 0x8194 | 0x7594 | 0x134 |
_wcslwr | 0x0 | 0x40613c | 0x8198 | 0x7598 | 0x52c |
NtQueryInformationProcess | 0x0 | 0x406140 | 0x819c | 0x759c | 0xe7 |
RtlGetCurrentPeb | 0x0 | 0x406144 | 0x81a0 | 0x75a0 | 0x248 |
swprintf | 0x0 | 0x406148 | 0x81a4 | 0x75a4 | 0x569 |
wcsncpy | 0x0 | 0x40614c | 0x81a8 | 0x75a8 | 0x57a |
NtYieldExecution | 0x0 | 0x406150 | 0x81ac | 0x75ac | 0x166 |
NtTerminateProcess | 0x0 | 0x406154 | 0x81b0 | 0x75b0 | 0x150 |
RtlCreateHeap | 0x0 | 0x406158 | 0x81b4 | 0x75b4 | 0x1cc |
mbstowcs | 0x0 | 0x40615c | 0x81b8 | 0x75b8 | 0x54e |
sprintf | 0x0 | 0x406160 | 0x81bc | 0x75bc | 0x557 |
_stricmp | 0x0 | 0x406164 | 0x81c0 | 0x75c0 | 0x51f |
memset | 0x0 | 0x406168 | 0x81c4 | 0x75c4 | 0x553 |
_chkstk | 0x0 | 0x40616c | 0x81c8 | 0x75c8 | 0x50f |
memcpy | 0x0 | 0x406170 | 0x81cc | 0x75cc | 0x551 |
_allrem | 0x0 | 0x406174 | 0x81d0 | 0x75d0 | 0x507 |
RtlUnwind | 0x0 | 0x406178 | 0x81d4 | 0x75d4 | 0x341 |
KERNEL32.dll (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExpandEnvironmentStringsW | 0x0 | 0x406000 | 0x805c | 0x745c | 0x11d |
CreateThread | 0x0 | 0x406004 | 0x8060 | 0x7460 | 0xb5 |
DeleteFileA | 0x0 | 0x406008 | 0x8064 | 0x7464 | 0xd3 |
SetFileAttributesW | 0x0 | 0x40600c | 0x8068 | 0x7468 | 0x461 |
ResumeThread | 0x0 | 0x406010 | 0x806c | 0x746c | 0x413 |
DeleteFileW | 0x0 | 0x406014 | 0x8070 | 0x7470 | 0xd6 |
GetWindowsDirectoryW | 0x0 | 0x406018 | 0x8074 | 0x7474 | 0x2af |
CloseHandle | 0x0 | 0x40601c | 0x8078 | 0x7478 | 0x52 |
OutputDebugStringA | 0x0 | 0x406020 | 0x807c | 0x747c | 0x389 |
GetCurrentThreadId | 0x0 | 0x406024 | 0x8080 | 0x7480 | 0x1c5 |
GetShortPathNameW | 0x0 | 0x406028 | 0x8084 | 0x7484 | 0x261 |
FindNextFileW | 0x0 | 0x40602c | 0x8088 | 0x7488 | 0x145 |
GetModuleHandleA | 0x0 | 0x406030 | 0x808c | 0x748c | 0x215 |
GetModuleFileNameA | 0x0 | 0x406034 | 0x8090 | 0x7490 | 0x213 |
WaitForMultipleObjects | 0x0 | 0x406038 | 0x8094 | 0x7494 | 0x4f7 |
DeviceIoControl | 0x0 | 0x40603c | 0x8098 | 0x7498 | 0xdd |
CreateFileMappingA | 0x0 | 0x406040 | 0x809c | 0x749c | 0x89 |
LoadLibraryA | 0x0 | 0x406044 | 0x80a0 | 0x74a0 | 0x33c |
GetFullPathNameW | 0x0 | 0x406048 | 0x80a4 | 0x74a4 | 0x1fb |
ExitProcess | 0x0 | 0x40604c | 0x80a8 | 0x74a8 | 0x119 |
GetCommandLineW | 0x0 | 0x406050 | 0x80ac | 0x74ac | 0x187 |
GetComputerNameA | 0x0 | 0x406054 | 0x80b0 | 0x74b0 | 0x18c |
CreateFileA | 0x0 | 0x406058 | 0x80b4 | 0x74b4 | 0x88 |
GetFileSize | 0x0 | 0x40605c | 0x80b8 | 0x74b8 | 0x1f0 |
FindFirstFileW | 0x0 | 0x406060 | 0x80bc | 0x74bc | 0x139 |
SetFilePointer | 0x0 | 0x406064 | 0x80c0 | 0x74c0 | 0x466 |
GetLocaleInfoA | 0x0 | 0x406068 | 0x80c4 | 0x74c4 | 0x204 |
MapViewOfFile | 0x0 | 0x40606c | 0x80c8 | 0x74c8 | 0x357 |
UnmapViewOfFile | 0x0 | 0x406070 | 0x80cc | 0x74cc | 0x4d6 |
GetDriveTypeW | 0x0 | 0x406074 | 0x80d0 | 0x74d0 | 0x1d3 |
FreeLibrary | 0x0 | 0x406078 | 0x80d4 | 0x74d4 | 0x162 |
HeapAlloc | 0x0 | 0x40607c | 0x80d8 | 0x74d8 | 0x2cb |
InterlockedIncrement | 0x0 | 0x406080 | 0x80dc | 0x74dc | 0x2ef |
MoveFileExW | 0x0 | 0x406084 | 0x80e0 | 0x74e0 | 0x360 |
InterlockedDecrement | 0x0 | 0x406088 | 0x80e4 | 0x74e4 | 0x2eb |
GetCurrentProcess | 0x0 | 0x40608c | 0x80e8 | 0x74e8 | 0x1c0 |
GetLogicalDriveStringsW | 0x0 | 0x406090 | 0x80ec | 0x74ec | 0x208 |
HeapFree | 0x0 | 0x406094 | 0x80f0 | 0x74f0 | 0x2cf |
WaitForSingleObject | 0x0 | 0x406098 | 0x80f4 | 0x74f4 | 0x4f9 |
GetSystemDefaultLCID | 0x0 | 0x40609c | 0x80f8 | 0x74f8 | 0x26b |
OutputDebugStringW | 0x0 | 0x4060a0 | 0x80fc | 0x74fc | 0x38a |
GetTickCount | 0x0 | 0x4060a4 | 0x8100 | 0x7500 | 0x293 |
GetProcessHeap | 0x0 | 0x4060a8 | 0x8104 | 0x7504 | 0x24a |
GetLocalTime | 0x0 | 0x4060ac | 0x8108 | 0x7508 | 0x203 |
GlobalAlloc | 0x0 | 0x4060b0 | 0x810c | 0x750c | 0x2b3 |
GetSystemDirectoryW | 0x0 | 0x4060b4 | 0x8110 | 0x7510 | 0x270 |
TerminateThread | 0x0 | 0x4060b8 | 0x8114 | 0x7514 | 0x4c1 |
Sleep | 0x0 | 0x4060bc | 0x8118 | 0x7518 | 0x4b2 |
CopyFileW | 0x0 | 0x4060c0 | 0x811c | 0x751c | 0x75 |
LeaveCriticalSection | 0x0 | 0x4060c4 | 0x8120 | 0x7520 | 0x339 |
GetFileAttributesW | 0x0 | 0x4060c8 | 0x8124 | 0x7524 | 0x1ea |
CreateProcessA | 0x0 | 0x4060cc | 0x8128 | 0x7528 | 0xa4 |
ReadFile | 0x0 | 0x4060d0 | 0x812c | 0x752c | 0x3c0 |
CreateFileW | 0x0 | 0x4060d4 | 0x8130 | 0x7530 | 0x8f |
ExitThread | 0x0 | 0x4060d8 | 0x8134 | 0x7534 | 0x11a |
SetThreadPriority | 0x0 | 0x4060dc | 0x8138 | 0x7538 | 0x499 |
FlushFileBuffers | 0x0 | 0x4060e0 | 0x813c | 0x753c | 0x157 |
GetTempPathW | 0x0 | 0x4060e4 | 0x8140 | 0x7540 | 0x285 |
GetFileSizeEx | 0x0 | 0x4060e8 | 0x8144 | 0x7544 | 0x1f1 |
GetLastError | 0x0 | 0x4060ec | 0x8148 | 0x7548 | 0x202 |
GetProcAddress | 0x0 | 0x4060f0 | 0x814c | 0x754c | 0x245 |
SetVolumeLabelW | 0x0 | 0x4060f4 | 0x8150 | 0x7550 | 0x4a9 |
MoveFileW | 0x0 | 0x4060f8 | 0x8154 | 0x7554 | 0x363 |
EnterCriticalSection | 0x0 | 0x4060fc | 0x8158 | 0x7558 | 0xee |
GlobalFree | 0x0 | 0x406100 | 0x815c | 0x755c | 0x2ba |
FindClose | 0x0 | 0x406104 | 0x8160 | 0x7560 | 0x12e |
WriteFile | 0x0 | 0x406108 | 0x8164 | 0x7564 | 0x525 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
file2.exe | 1 | 0x00400000 | 0x0041CFFF | Relevant Image |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
file2.exe | 1 | 0x00400000 | 0x0041CFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
file2.exe | 1 | 0x00400000 | 0x0041CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
kvr.exe | 3 | 0x00400000 | 0x0041CFFF | Relevant Image |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Satana | Satana ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\coronaVi2022@protonmail.ch___Parameterinfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\coronaVi2022@protonmail.ch___UiInfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\coronaVi2022@protonmail.ch___Parameterinfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\coronaVi2022@protonmail.ch___UiInfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___ParameterInfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___SplashScreen.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___watermark.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\coronaVi2022@protonmail.ch___BOOTSECT.bak | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\coronaVi2022@protonmail.ch___OfficeUpdateSchedule.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash@2x.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash_11-lic.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\coronaVi2022@protonmail.ch___win32_CopyDrop32x32.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\coronaVi2022@protonmail.ch___jvm.hprof.txt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\coronaVi2022@protonmail.ch___FileSystemMetadata.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\coronaVi2022@protonmail.ch___THIRDPARTYLICENSEREADME-JAVAFX.txt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office16\coronaVi2022@protonmail.ch___SLERROR.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office16\coronaVi2022@protonmail.ch___OSPP.vbs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\sxr.exe | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4010af |
Size Of Code | 0x200 |
Size Of Initialized Data | 0x600 |
File Type | FileType.executable |
Subsystem | Subsystem.native |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 13:02:36+00:00 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x102 | 0x200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 3.49 |
.rdata | 0x402000 | 0x4cc | 0x600 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.16 |
Imports (1)
»
ntdll.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NtDeviceIoControlFile | 0x0 | 0x402000 | 0x2400 | 0xa00 | 0x8e |
NtTerminateProcess | 0x0 | 0x402004 | 0x2404 | 0xa04 | 0x150 |
RtlInitUnicodeString | 0x0 | 0x402008 | 0x2408 | 0xa08 | 0x26e |
RtlFreeUnicodeString | 0x0 | 0x40200c | 0x240c | 0xa0c | 0x23e |
NtDisplayString | 0x0 | 0x402010 | 0x2410 | 0xa10 | 0x8f |
NtCreateFile | 0x0 | 0x402014 | 0x2414 | 0xa14 | 0x6f |
NtClose | 0x0 | 0x402018 | 0x2418 | 0xa18 | 0x63 |
NtDelayExecution | 0x0 | 0x40201c | 0x241c | 0xa1c | 0x87 |
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»