Malicious
Classifications
Wiper Ransomware
Threat Names
Mal/Generic-S Gen:Heur.Ransom.REntS.Gen.1 Gen:Heur.Ransom.RTH.1
Dynamic Analysis Report
Created on 2021-03-23T10:19:00
covid.exe
Windows Exe (x86-32)
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
File Reputation Information
»
Verdict |
malicious
|
Names | Mal/Generic-S |
AV Matches (1)
»
Threat Name | Verdict |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4049f2 |
Size Of Code | 0x2a00 |
Size Of Initialized Data | 0x1400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2100-03-04 21:02:54+00:00 |
Version Information (11)
»
Comments | - |
CompanyName | - |
FileDescription | covid |
FileVersion | 1.0.0.0 |
InternalName | covid.exe |
LegalCopyright | Copyright © 2021 |
LegalTrademarks | - |
OriginalFilename | covid.exe |
ProductName | covid |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x29f8 | 0x2a00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.56 |
.rsrc | 0x406000 | 0x10f0 | 0x1200 | 0x2c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.08 |
.reloc | 0x408000 | 0xc | 0x200 | 0x3e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x402000 | 0x49c6 | 0x2bc6 | 0x0 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
covid.exe | 1 | 0x00400000 | 0x00409FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
C:\Users\RDhJ0CNFevzX\Desktop\0jVFU_fwepsE1hnB.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\6an92ONxDM17h_.flv.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\88GtSFKzH73_vJ.avi.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\ADwpnfaKGM4F2saUkB.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\aL5rm1Z_3UQgZuI.wav.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\AOrbZA5hkn0z42FZmF.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\bicJkMmQ4B.ppt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\covid.exe.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\-TZ5rzCIOrbdbR.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\35-jfpA-mtUPvs5gV4mr.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\4qcvOht-riX9J3ZGd2AN.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\5eGY_O6oAQYCeYF.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\7IGp2H4UWA.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\8_L0.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\aEzzAV.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\CfMroH.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\desktop.ini.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\I7J71mzGsYDYCBoUz.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Ieiqp5qQg.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\iotg5jb-wcu3hO-.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\iTLuTdWLR4vAu.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Izk7bTMXw-1.png.ncovid | Dropped File | Binary |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\ljeI.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\ljhkhNwA93064H5W.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\N0pnuWNn.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Rne6z7RphV.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\soB3UY84J.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\V1CR3ZY6XRVc7QPNQ2G3.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\WTv_2d9vuAAmrz9WS353.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Y412g.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\yQmXMOnbtf7h7HFf_BA.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Camera Roll\desktop.ini.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\0zlvDRYF 8_DNOz.gif.ncovid | Dropped File | Binary |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\4Sf2rxZ-7lb.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\C_3uY_z.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\dYaA_F5bFWX YC4AE.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\e8vhItq tNtLt5TtE.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\ffD28EQZFv-o1x82.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\Fli1a9fCj4gSy.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\fMtuTrlNKaoFFoK0.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\lO0esS 0HHYKS.jpg.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\OgmalY.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\q2MHsGKaQ.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\rJAWas8pDAbmp.png.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\Vnz6_hUjAg9jH3t30.bmp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\vuyif.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\vwnzeoQ1jDssMQY.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gQVD1CNgqQdWgWk\z-t5SKb go1vNMcR4.gif.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Saved Pictures\desktop.ini.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\0Qov66TFlL71Vr.ods.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\568KyO2WPqAyIkKb6J.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\70YjXp03IqF wav.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\76lI28SHkOO1S5RZA.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\7p-yfll45o4qAG-.rtf.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\9duwNE_vpUogUDNE1V.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\9Jh63.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\9pqheIL3CaaI.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\axFXeggj.pdf.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\bTgBDM_BLCIn 9g.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\c--oDETPCZEmFkX9R.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\c1uWbuECVbO7GtKW39T.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\cDJMQ767y 9NDJF.csv.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\cWSN5bi9vhUj73qO.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\desktop.ini.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\e cwv2Je8.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\e3we HsPkukwCQ_rD1.pdf.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\EgsQo0UhXKVeTvl3SU4.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Ez15cqKrqd8C42.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\fIJgDYKYDnkfXH1E5C.csv.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\FKV_Um7s1AtkG6SwRc.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\fvN5PmwQa.odt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\HjIAFUmQscCo 2L.ppt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\hJTYe7eOwos.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\JDRimLeWPyHLTdjUoJ.ppt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Ji5Tbajt.xls.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\jXu_ngddt0WmrHz3gEIW.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\KtLEO.rtf.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Lgwxj.doc.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Mho1kAIrYCh.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\n4XNFeLI8Mi4SE.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\nnMQFmGNl.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\NOwnJ6AGI50mPI.pps.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\nzlHK8NwMZ86oh.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\OKqg.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\pEpUMw_9Zcoad.csv.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Pxigi.rtf.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\qes9g8fLDZ.odt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\QOSULyfBxbm7V7 _F.odt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\rHZ_lf-3p.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\sD-nmkQy yW.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\UjcF5Fxqgs2AfHh9_uwc.doc.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\uK_cajxxD7q1FH6.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\VgCrC4n9vd-j-Mu8i.pptx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\VkzL2G-1q5yzVgCvx.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\XGb73bZ.odt.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\XuhXtcsvkk4kAz8BQGV3.docx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\XzpwLTxYTuIIcq9.xlsx.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\yGgVErNaD-GX.odp.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Yngu.csv.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Outlook Files\achoo@gdllo.de.pst.ncovid | Dropped File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\___RECOVER__FILES__.ncovid.txt | Dropped File | Text |
clean
|
...
|
»