VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Spyware
Dropper
|
Threat Names: |
Gen:Variant.Razy.601945
Gen:Variant.Razy.484160
Win32.Trojan.Genkryptik
|
msader15.dll.exe
Windows Exe (x86-32)
Created at 2020-01-21T07:56:00
Kernel Graph 1

Code Block #1 (EP #1)
»
Information | Value |
---|---|
Trigger | KiRetireDpcList+0x1b5 |
Start Address | 0xfffffa80018ee84c |
Execution Path #1 (length: 1, count: 1, processes: 1)
»
Information | Value |
---|---|
Sequence Length | 1 |
Processes
»
Process | Count |
---|---|
Process 44 (lsass.exe, PID: 452) | 1 |
Sequence
»
Symbol | Parameters |
---|---|
ExQueueWorkItem | WorkItem_ptr = 0xfffffa80019b62f4, WorkItem_deref_List.Flink_unk = 0x0, WorkItem_deref_List.Blink_unk = 0x0, WorkItem_deref_WorkerRoutine_unk = 0xfffffa80019baed9, WorkItem_deref_Parameter_ptr = 0xfffffa80019b60b4, QueueType_unk = 0x1, WorkItem_ptr_out = 0xfffffa80019b62f4, WorkItem_deref_List.Flink_unk_out = 0x0, WorkItem_deref_List.Blink_unk_out = 0x0, WorkItem_deref_WorkerRoutine_unk_out = 0xfffffa80019baed9, WorkItem_deref_Parameter_ptr_out = 0xfffffa80019b60b4 |
Code Block #2 (EP #2)
»
Information | Value |
---|---|
Trigger | ExpWorkerThread+0x10f |
Start Address | 0xfffffa80019baed9 |
Execution Path #2 (length: 1, count: 1, processes: 1 incomplete)
»
Information | Value |
---|---|
Sequence Length | 1 |
Processes
»
Process | Count |
---|---|
Process 34 (System, PID: 4) | 1 |
Sequence
»
Symbol | Parameters |
---|---|
KeDelayExecutionThread | WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880027c75a8, Interval = -1215842058 |