VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Spyware
|
Threat Names: |
Gen:Variant.Ransom.GoRansom.2
|
I1JxvGfOI7P4ZS9i.exe
Windows Exe (x86-64)
Created at 2020-07-20T18:10:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I1JxvGfOI7P4ZS9i.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x45a710 |
Size Of Code | 0x18ac00 |
Size Of Initialized Data | 0x1e200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (14)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x18ab19 | 0x18ac00 | 0x600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.94 |
.rdata | 0x58c000 | 0x19f3ce | 0x19f400 | 0x18b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x72c000 | 0x429a8 | 0x1e200 | 0x32a600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.02 |
/4 | 0x76f000 | 0x119 | 0x200 | 0x348800 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.83 |
/19 | 0x770000 | 0x33ea9 | 0x34000 | 0x348a00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.99 |
/32 | 0x7a4000 | 0xd8ba | 0xda00 | 0x37ca00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.94 |
/46 | 0x7b2000 | 0x39c2 | 0x3a00 | 0x38a400 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.97 |
/63 | 0x7b6000 | 0x6513 | 0x6600 | 0x38de00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.98 |
/80 | 0x7bd000 | 0x28 | 0x200 | 0x394400 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.7 |
/99 | 0x7be000 | 0x7270d | 0x72800 | 0x394600 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 8.0 |
/112 | 0x831000 | 0x3a939 | 0x3aa00 | 0x406e00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 8.0 |
/124 | 0x86c000 | 0x12f6e | 0x13000 | 0x441800 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.8 |
.idata | 0x87f000 | 0x3b4 | 0x400 | 0x454800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.1 |
.symtab | 0x880000 | 0x42701 | 0x42800 | 0x454c00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.37 |
Imports (1)
»
KERNEL32.DLL (32)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x72c020 | 0x32c020 | 0x32a620 | 0x0 |
WriteConsoleW | 0x0 | 0x72c028 | 0x32c028 | 0x32a628 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x72c030 | 0x32c030 | 0x32a630 | 0x0 |
WaitForSingleObject | 0x0 | 0x72c038 | 0x32c038 | 0x32a638 | 0x0 |
VirtualQuery | 0x0 | 0x72c040 | 0x32c040 | 0x32a640 | 0x0 |
VirtualFree | 0x0 | 0x72c048 | 0x32c048 | 0x32a648 | 0x0 |
VirtualAlloc | 0x0 | 0x72c050 | 0x32c050 | 0x32a650 | 0x0 |
SwitchToThread | 0x0 | 0x72c058 | 0x32c058 | 0x32a658 | 0x0 |
SetWaitableTimer | 0x0 | 0x72c060 | 0x32c060 | 0x32a660 | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x72c068 | 0x32c068 | 0x32a668 | 0x0 |
SetProcessPriorityBoost | 0x0 | 0x72c070 | 0x32c070 | 0x32a670 | 0x0 |
SetEvent | 0x0 | 0x72c078 | 0x32c078 | 0x32a678 | 0x0 |
SetErrorMode | 0x0 | 0x72c080 | 0x32c080 | 0x32a680 | 0x0 |
SetConsoleCtrlHandler | 0x0 | 0x72c088 | 0x32c088 | 0x32a688 | 0x0 |
LoadLibraryA | 0x0 | 0x72c090 | 0x32c090 | 0x32a690 | 0x0 |
LoadLibraryW | 0x0 | 0x72c098 | 0x32c098 | 0x32a698 | 0x0 |
GetSystemInfo | 0x0 | 0x72c0a0 | 0x32c0a0 | 0x32a6a0 | 0x0 |
GetSystemDirectoryA | 0x0 | 0x72c0a8 | 0x32c0a8 | 0x32a6a8 | 0x0 |
GetStdHandle | 0x0 | 0x72c0b0 | 0x32c0b0 | 0x32a6b0 | 0x0 |
GetQueuedCompletionStatus | 0x0 | 0x72c0b8 | 0x32c0b8 | 0x32a6b8 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x72c0c0 | 0x32c0c0 | 0x32a6c0 | 0x0 |
GetProcAddress | 0x0 | 0x72c0c8 | 0x32c0c8 | 0x32a6c8 | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x72c0d0 | 0x32c0d0 | 0x32a6d0 | 0x0 |
GetConsoleMode | 0x0 | 0x72c0d8 | 0x32c0d8 | 0x32a6d8 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x72c0e0 | 0x32c0e0 | 0x32a6e0 | 0x0 |
ExitProcess | 0x0 | 0x72c0e8 | 0x32c0e8 | 0x32a6e8 | 0x0 |
DuplicateHandle | 0x0 | 0x72c0f0 | 0x32c0f0 | 0x32a6f0 | 0x0 |
CreateThread | 0x0 | 0x72c0f8 | 0x32c0f8 | 0x32a6f8 | 0x0 |
CreateIoCompletionPort | 0x0 | 0x72c100 | 0x32c100 | 0x32a700 | 0x0 |
CreateEventA | 0x0 | 0x72c108 | 0x32c108 | 0x32a708 | 0x0 |
CloseHandle | 0x0 | 0x72c110 | 0x32c110 | 0x32a710 | 0x0 |
AddVectoredExceptionHandler | 0x0 | 0x72c118 | 0x32c118 | 0x32a718 | 0x0 |
Memory Dumps (7)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
i1jxvgfoi7p4zs9i.exe | 1 | 0x00400000 | 0x008C2FFF | Relevant Image |
![]() |
64-bit | 0x00458617 |
![]() |
![]() |
...
|
buffer | 1 | 0xC0000D0000 | 0xC0000D1FFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0xC00033E000 | 0xC00033FFFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0xC0004EE000 | 0xC0004EFFFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0xC000614000 | 0xC000623FFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0xC000704000 | 0xC000739FFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
![]() |
...
|
i1jxvgfoi7p4zs9i.exe | 1 | 0x00400000 | 0x008C2FFF | Final Dump |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.GoRansom.2 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pmkdobtkvlgb.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kplgbgkckbc.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Document Themes 14\Theme Fonts\HOW TO RESTORE YOUR FILES.TXT | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.msi.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.ijikpvj | Dropped File | Stream |
Unknown
|
...
|
»