VTI SCORE: 91/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: | - |
such-crypt.exe
Windows Exe (x86-64)
Created at 2020-06-11T00:24:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x45f3f0 |
Size Of Code | 0xd4000 |
Size Of Initialized Data | 0x18a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xd3f5b | 0xd4000 | 0x600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.95 |
.rdata | 0x4d5000 | 0xefa1a | 0xefc00 | 0xd4600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.23 |
.data | 0x5c5000 | 0x48348 | 0x18a00 | 0x1c4200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.78 |
.idata | 0x60e000 | 0x442 | 0x600 | 0x1dcc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.44 |
.symtab | 0x60f000 | 0x4 | 0x200 | 0x1dd200 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
kernel32.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x5c5020 | 0x20e312 | 0x1dcf12 | 0x0 |
WriteConsoleW | 0x0 | 0x5c5028 | 0x20e31a | 0x1dcf1a | 0x0 |
WaitForMultipleObjects | 0x0 | 0x5c5030 | 0x20e322 | 0x1dcf22 | 0x0 |
WaitForSingleObject | 0x0 | 0x5c5038 | 0x20e32a | 0x1dcf2a | 0x0 |
VirtualQuery | 0x0 | 0x5c5040 | 0x20e332 | 0x1dcf32 | 0x0 |
VirtualFree | 0x0 | 0x5c5048 | 0x20e33a | 0x1dcf3a | 0x0 |
VirtualAlloc | 0x0 | 0x5c5050 | 0x20e342 | 0x1dcf42 | 0x0 |
SwitchToThread | 0x0 | 0x5c5058 | 0x20e34a | 0x1dcf4a | 0x0 |
SuspendThread | 0x0 | 0x5c5060 | 0x20e352 | 0x1dcf52 | 0x0 |
SetWaitableTimer | 0x0 | 0x5c5068 | 0x20e35a | 0x1dcf5a | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x5c5070 | 0x20e362 | 0x1dcf62 | 0x0 |
SetProcessPriorityBoost | 0x0 | 0x5c5078 | 0x20e36a | 0x1dcf6a | 0x0 |
SetEvent | 0x0 | 0x5c5080 | 0x20e372 | 0x1dcf72 | 0x0 |
SetErrorMode | 0x0 | 0x5c5088 | 0x20e37a | 0x1dcf7a | 0x0 |
SetConsoleCtrlHandler | 0x0 | 0x5c5090 | 0x20e382 | 0x1dcf82 | 0x0 |
ResumeThread | 0x0 | 0x5c5098 | 0x20e38a | 0x1dcf8a | 0x0 |
PostQueuedCompletionStatus | 0x0 | 0x5c50a0 | 0x20e392 | 0x1dcf92 | 0x0 |
LoadLibraryA | 0x0 | 0x5c50a8 | 0x20e39a | 0x1dcf9a | 0x0 |
LoadLibraryW | 0x0 | 0x5c50b0 | 0x20e3a2 | 0x1dcfa2 | 0x0 |
SetThreadContext | 0x0 | 0x5c50b8 | 0x20e3aa | 0x1dcfaa | 0x0 |
GetThreadContext | 0x0 | 0x5c50c0 | 0x20e3b2 | 0x1dcfb2 | 0x0 |
GetSystemInfo | 0x0 | 0x5c50c8 | 0x20e3ba | 0x1dcfba | 0x0 |
GetSystemDirectoryA | 0x0 | 0x5c50d0 | 0x20e3c2 | 0x1dcfc2 | 0x0 |
GetStdHandle | 0x0 | 0x5c50d8 | 0x20e3ca | 0x1dcfca | 0x0 |
GetQueuedCompletionStatus | 0x0 | 0x5c50e0 | 0x20e3d2 | 0x1dcfd2 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x5c50e8 | 0x20e3da | 0x1dcfda | 0x0 |
GetProcAddress | 0x0 | 0x5c50f0 | 0x20e3e2 | 0x1dcfe2 | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x5c50f8 | 0x20e3ea | 0x1dcfea | 0x0 |
GetConsoleMode | 0x0 | 0x5c5100 | 0x20e3f2 | 0x1dcff2 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x5c5108 | 0x20e3fa | 0x1dcffa | 0x0 |
ExitProcess | 0x0 | 0x5c5110 | 0x20e402 | 0x1dd002 | 0x0 |
DuplicateHandle | 0x0 | 0x5c5118 | 0x20e40a | 0x1dd00a | 0x0 |
CreateThread | 0x0 | 0x5c5120 | 0x20e412 | 0x1dd012 | 0x0 |
CreateIoCompletionPort | 0x0 | 0x5c5128 | 0x20e41a | 0x1dd01a | 0x0 |
CreateEventA | 0x0 | 0x5c5130 | 0x20e422 | 0x1dd022 | 0x0 |
CloseHandle | 0x0 | 0x5c5138 | 0x20e42a | 0x1dd02a | 0x0 |
AddVectoredExceptionHandler | 0x0 | 0x5c5140 | 0x20e432 | 0x1dd032 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
such-crypt.exe | 1 | 0x00400000 | 0x0060FFFF | Relevant Image |
![]() |
64-bit | 0x004366A0 |
![]() |
![]() |
...
|
such-crypt.exe | 1 | 0x00400000 | 0x0060FFFF | Process Termination |
![]() |
64-bit | - |
![]() |
![]() |
...
|
C:\Users\FD1HVy\Desktop\3zc9rz__.bmp.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\42wj0K3ANT1mI7xiZrH.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\8I8qAm.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\8P2xnD_.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\9P9-6.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\3vfsA8BVoOQZ_Fks.wav.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\C- Qb8g2eM.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\HYpdhBR65SbzGnrzRXP.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\I9Y_rV sAretLr30cEG.mkv.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\Oi JQbJkF0.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\h9B-rnLmlAx2K0BQN.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\qwvkoqI.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\APtvYJ6hbBpaVagvM\whEuN.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Bqxu_-C2.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\C ewIvT0ae.jpg.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HDsD6NZZVHzjXXHkGz3.jpg.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HGX3.jpg.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\JUbwbGFrm_hWB U6PIK.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\JdTm9BwwQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\N1tT.wav.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\O7eUiQojZP.jpg.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OyWALyc.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\PE67dubZQXEny5.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Q5TWSMOvOpUK.pps.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Qrw09Owb.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\VvilGlKrXX.m4a.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XWMuj.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\b6 m.mkv.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cNmXtvjdpH.png | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\e6RSXqgLrY.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\iy P1dnliprHymbIs.mp3.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mkEqa98u7.pdf.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pFd4z4yml5djyvTO.swf.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pGOHGJnWHNnRxp.gif.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\qIKtcsS.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rMZI7PJITmi50kwHk5.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\s7W4t.jpg.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\uAlQCDw2mJL9DHJSBQNO.m4a.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\upv4OEbnF.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\v5_y.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vm2mXH0LrVGZti6ho.wav.mwahahah | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\wMAKMJ7eooO4tf-aLep.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\yS5XjosA_I.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zEu2NO3s7SVXyOSDwmPz.flv | Modified File | Stream |
Unknown
|
...
|
»