VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.Locked.3D08AF5C
Gen:Variant.Ransom.Aviso.2
Gen:Variant.Ursu.519232
...
|
Angry Lola Loud Ran$omware.exe
Windows Exe (x86-32)
Created at 2020-12-18T11:47:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Angry Lola Loud Ran$omware.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0xadf920 |
Size Of Code | 0x43000 |
Size Of Initialized Data | 0x630000 |
Size Of Uninitialized Data | 0x69c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 21:32:28+00:00 |
Version Information (3)
»
CompiledScript | AutoIt v3 Script: 3, 3, 8, 1 |
FileDescription | - |
FileVersion | 3, 3, 8, 1 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x69c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0xa9d000 | 0x43000 | 0x42c00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0xae0000 | 0x630000 | 0x62f200 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.21 |
Imports (16)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x110ee3c | 0xd0ee3c | 0x671e3c | 0x0 |
GetProcAddress | 0x0 | 0x110ee40 | 0xd0ee40 | 0x671e40 | 0x0 |
VirtualProtect | 0x0 | 0x110ee44 | 0xd0ee44 | 0x671e44 | 0x0 |
VirtualAlloc | 0x0 | 0x110ee48 | 0xd0ee48 | 0x671e48 | 0x0 |
VirtualFree | 0x0 | 0x110ee4c | 0xd0ee4c | 0x671e4c | 0x0 |
ExitProcess | 0x0 | 0x110ee50 | 0xd0ee50 | 0x671e50 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetAce | 0x0 | 0x110ee58 | 0xd0ee58 | 0x671e58 | 0x0 |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Remove | 0x0 | 0x110ee60 | 0xd0ee60 | 0x671e60 | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSaveFileNameW | 0x0 | 0x110ee68 | 0xd0ee68 | 0x671e68 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LineTo | 0x0 | 0x110ee70 | 0xd0ee70 | 0x671e70 | 0x0 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x110ee78 | 0xd0ee78 | 0x671e78 | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | 0x0 | 0x110ee80 | 0xd0ee80 | 0x671e80 | 0x0 |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantInit | 0x8 | 0x110ee88 | 0xd0ee88 | 0x671e88 | - |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumProcesses | 0x0 | 0x110ee90 | 0xd0ee90 | 0x671e90 | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragFinish | 0x0 | 0x110ee98 | 0xd0ee98 | 0x671e98 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x110eea0 | 0xd0eea0 | 0x671ea0 | 0x0 |
USERENV.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadUserProfileW | 0x0 | 0x110eea8 | 0xd0eea8 | 0x671ea8 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x110eeb0 | 0xd0eeb0 | 0x671eb0 | 0x0 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FtpOpenFileW | 0x0 | 0x110eeb8 | 0xd0eeb8 | 0x671eb8 | 0x0 |
WINMM.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x110eec0 | 0xd0eec0 | 0x671ec0 | 0x0 |
WSOCK32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
recv | 0x10 | 0x110eec8 | 0xd0eec8 | 0x671ec8 | - |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Locked.3D08AF5C |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\autD509.tmp | Dropped File | CAB |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Archive Information
»
Number of Files | 1 |
Number of Folders | 0 |
Size of Packed Archive Contents | 89.50 KB |
Size of Unpacked Archive Contents | 89.50 KB |
File Format | cab |
Contents (1)
»
Filename | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Actions |
---|---|---|---|---|---|---|
cryptbase.dll | 89.50 KB | 89.50 KB | MSZip |
![]() |
2015-08-29 16:58 (UTC+2) |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.Aviso.2 |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp/64.cab | Dropped File | CAB |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Archive Information
»
Number of Files | 1 |
Number of Folders | 0 |
Size of Packed Archive Contents | 106.00 KB |
Size of Unpacked Archive Contents | 106.00 KB |
File Format | cab |
Contents (1)
»
Filename | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Actions |
---|---|---|---|---|---|---|
cryptbase.dll | 106.00 KB | 106.00 KB | MSZip |
![]() |
2015-08-29 16:58 (UTC+2) |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ursu.519232 |
Malicious
|
cryptbase.dll | Embedded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x10002f21 |
Size Of Code | 0xd600 |
Size Of Initialized Data | 0xac00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2015-08-29 11:58:39+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0xd59b | 0xd600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.72 |
.rdata | 0x1000f000 | 0x63e6 | 0x6400 | 0xda00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.82 |
.data | 0x10016000 | 0x323c | 0x1400 | 0x13e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.73 |
.rsrc | 0x1001a000 | 0x1e0 | 0x200 | 0x15200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x1001b000 | 0x11b0 | 0x1200 | 0x15400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.47 |
Imports (1)
»
KERNEL32.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCommandLineA | 0x0 | 0x1000f000 | 0x14e6c | 0x1386c | 0x186 |
WinExec | 0x0 | 0x1000f004 | 0x14e70 | 0x13870 | 0x512 |
EncodePointer | 0x0 | 0x1000f008 | 0x14e74 | 0x13874 | 0xea |
DecodePointer | 0x0 | 0x1000f00c | 0x14e78 | 0x13878 | 0xca |
GetLastError | 0x0 | 0x1000f010 | 0x14e7c | 0x1387c | 0x202 |
ExitProcess | 0x0 | 0x1000f014 | 0x14e80 | 0x13880 | 0x119 |
GetModuleHandleExW | 0x0 | 0x1000f018 | 0x14e84 | 0x13884 | 0x217 |
GetProcAddress | 0x0 | 0x1000f01c | 0x14e88 | 0x13888 | 0x245 |
MultiByteToWideChar | 0x0 | 0x1000f020 | 0x14e8c | 0x1388c | 0x367 |
WideCharToMultiByte | 0x0 | 0x1000f024 | 0x14e90 | 0x13890 | 0x511 |
GetCurrentThreadId | 0x0 | 0x1000f028 | 0x14e94 | 0x13894 | 0x1c5 |
RaiseException | 0x0 | 0x1000f02c | 0x14e98 | 0x13898 | 0x3b1 |
RtlUnwind | 0x0 | 0x1000f030 | 0x14e9c | 0x1389c | 0x418 |
IsDebuggerPresent | 0x0 | 0x1000f034 | 0x14ea0 | 0x138a0 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x1000f038 | 0x14ea4 | 0x138a4 | 0x304 |
HeapSize | 0x0 | 0x1000f03c | 0x14ea8 | 0x138a8 | 0x2d4 |
HeapFree | 0x0 | 0x1000f040 | 0x14eac | 0x138ac | 0x2cf |
EnterCriticalSection | 0x0 | 0x1000f044 | 0x14eb0 | 0x138b0 | 0xee |
LeaveCriticalSection | 0x0 | 0x1000f048 | 0x14eb4 | 0x138b4 | 0x339 |
DeleteCriticalSection | 0x0 | 0x1000f04c | 0x14eb8 | 0x138b8 | 0xd1 |
UnhandledExceptionFilter | 0x0 | 0x1000f050 | 0x14ebc | 0x138bc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x1000f054 | 0x14ec0 | 0x138c0 | 0x4a5 |
SetLastError | 0x0 | 0x1000f058 | 0x14ec4 | 0x138c4 | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x1000f05c | 0x14ec8 | 0x138c8 | 0x2e3 |
Sleep | 0x0 | 0x1000f060 | 0x14ecc | 0x138cc | 0x4b2 |
GetCurrentProcess | 0x0 | 0x1000f064 | 0x14ed0 | 0x138d0 | 0x1c0 |
TerminateProcess | 0x0 | 0x1000f068 | 0x14ed4 | 0x138d4 | 0x4c0 |
TlsAlloc | 0x0 | 0x1000f06c | 0x14ed8 | 0x138d8 | 0x4c5 |
TlsGetValue | 0x0 | 0x1000f070 | 0x14edc | 0x138dc | 0x4c7 |
TlsSetValue | 0x0 | 0x1000f074 | 0x14ee0 | 0x138e0 | 0x4c8 |
TlsFree | 0x0 | 0x1000f078 | 0x14ee4 | 0x138e4 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x1000f07c | 0x14ee8 | 0x138e8 | 0x263 |
GetModuleHandleW | 0x0 | 0x1000f080 | 0x14eec | 0x138ec | 0x218 |
GetStdHandle | 0x0 | 0x1000f084 | 0x14ef0 | 0x138f0 | 0x264 |
WriteFile | 0x0 | 0x1000f088 | 0x14ef4 | 0x138f4 | 0x525 |
GetModuleFileNameW | 0x0 | 0x1000f08c | 0x14ef8 | 0x138f8 | 0x214 |
LoadLibraryExW | 0x0 | 0x1000f090 | 0x14efc | 0x138fc | 0x33e |
IsValidCodePage | 0x0 | 0x1000f094 | 0x14f00 | 0x13900 | 0x30a |
GetACP | 0x0 | 0x1000f098 | 0x14f04 | 0x13904 | 0x168 |
GetOEMCP | 0x0 | 0x1000f09c | 0x14f08 | 0x13908 | 0x237 |
GetCPInfo | 0x0 | 0x1000f0a0 | 0x14f0c | 0x1390c | 0x172 |
HeapAlloc | 0x0 | 0x1000f0a4 | 0x14f10 | 0x13910 | 0x2cb |
GetProcessHeap | 0x0 | 0x1000f0a8 | 0x14f14 | 0x13914 | 0x24a |
GetFileType | 0x0 | 0x1000f0ac | 0x14f18 | 0x13918 | 0x1f3 |
GetModuleFileNameA | 0x0 | 0x1000f0b0 | 0x14f1c | 0x1391c | 0x213 |
QueryPerformanceCounter | 0x0 | 0x1000f0b4 | 0x14f20 | 0x13920 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x1000f0b8 | 0x14f24 | 0x13924 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x1000f0bc | 0x14f28 | 0x13928 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x1000f0c0 | 0x14f2c | 0x1392c | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x1000f0c4 | 0x14f30 | 0x13930 | 0x161 |
HeapReAlloc | 0x0 | 0x1000f0c8 | 0x14f34 | 0x13934 | 0x2d2 |
LCMapStringW | 0x0 | 0x1000f0cc | 0x14f38 | 0x13938 | 0x32d |
OutputDebugStringW | 0x0 | 0x1000f0d0 | 0x14f3c | 0x1393c | 0x38a |
GetStringTypeW | 0x0 | 0x1000f0d4 | 0x14f40 | 0x13940 | 0x269 |
FlushFileBuffers | 0x0 | 0x1000f0d8 | 0x14f44 | 0x13944 | 0x157 |
GetConsoleCP | 0x0 | 0x1000f0dc | 0x14f48 | 0x13948 | 0x19a |
GetConsoleMode | 0x0 | 0x1000f0e0 | 0x14f4c | 0x1394c | 0x1ac |
SetStdHandle | 0x0 | 0x1000f0e4 | 0x14f50 | 0x13950 | 0x487 |
SetFilePointerEx | 0x0 | 0x1000f0e8 | 0x14f54 | 0x13954 | 0x467 |
WriteConsoleW | 0x0 | 0x1000f0ec | 0x14f58 | 0x13958 | 0x524 |
CloseHandle | 0x0 | 0x1000f0f0 | 0x14f5c | 0x1395c | 0x52 |
CreateFileW | 0x0 | 0x1000f0f4 | 0x14f60 | 0x13960 | 0x8f |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.Aviso.2 |
Malicious
|
cryptbase.dll | Embedded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x180000000 |
Entry Point | 0x180002fec |
Size Of Code | 0xe200 |
Size Of Initialized Data | 0xe800 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2015-08-29 11:58:02+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x180001000 | 0xe17f | 0xe200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.44 |
.rdata | 0x180010000 | 0x8f9e | 0x9000 | 0xe600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.1 |
.data | 0x180019000 | 0x3e30 | 0x1a00 | 0x17600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.17 |
.pdata | 0x18001d000 | 0xcd8 | 0xe00 | 0x19000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.61 |
.rsrc | 0x18001e000 | 0x1e0 | 0x200 | 0x19e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x18001f000 | 0x7ec | 0x800 | 0x1a000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.4 |
Imports (1)
»
KERNEL32.dll (66)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCommandLineA | 0x0 | 0x180010000 | 0x188b0 | 0x16eb0 | 0x18c |
WinExec | 0x0 | 0x180010008 | 0x188b8 | 0x16eb8 | 0x521 |
EncodePointer | 0x0 | 0x180010010 | 0x188c0 | 0x16ec0 | 0xee |
DecodePointer | 0x0 | 0x180010018 | 0x188c8 | 0x16ec8 | 0xcb |
GetLastError | 0x0 | 0x180010020 | 0x188d0 | 0x16ed0 | 0x208 |
ExitProcess | 0x0 | 0x180010028 | 0x188d8 | 0x16ed8 | 0x11f |
GetModuleHandleExW | 0x0 | 0x180010030 | 0x188e0 | 0x16ee0 | 0x21d |
GetProcAddress | 0x0 | 0x180010038 | 0x188e8 | 0x16ee8 | 0x24c |
MultiByteToWideChar | 0x0 | 0x180010040 | 0x188f0 | 0x16ef0 | 0x369 |
WideCharToMultiByte | 0x0 | 0x180010048 | 0x188f8 | 0x16ef8 | 0x520 |
GetCurrentThreadId | 0x0 | 0x180010050 | 0x18900 | 0x16f00 | 0x1cb |
RtlPcToFileHeader | 0x0 | 0x180010058 | 0x18908 | 0x16f08 | 0x421 |
RaiseException | 0x0 | 0x180010060 | 0x18910 | 0x16f10 | 0x3b4 |
RtlLookupFunctionEntry | 0x0 | 0x180010068 | 0x18918 | 0x16f18 | 0x41f |
RtlUnwindEx | 0x0 | 0x180010070 | 0x18920 | 0x16f20 | 0x425 |
IsDebuggerPresent | 0x0 | 0x180010078 | 0x18928 | 0x16f28 | 0x302 |
IsProcessorFeaturePresent | 0x0 | 0x180010080 | 0x18930 | 0x16f30 | 0x306 |
HeapSize | 0x0 | 0x180010088 | 0x18938 | 0x16f38 | 0x2dc |
HeapFree | 0x0 | 0x180010090 | 0x18940 | 0x16f40 | 0x2d7 |
EnterCriticalSection | 0x0 | 0x180010098 | 0x18948 | 0x16f48 | 0xf2 |
LeaveCriticalSection | 0x0 | 0x1800100a0 | 0x18950 | 0x16f50 | 0x33b |
DeleteCriticalSection | 0x0 | 0x1800100a8 | 0x18958 | 0x16f58 | 0xd2 |
RtlCaptureContext | 0x0 | 0x1800100b0 | 0x18960 | 0x16f60 | 0x418 |
RtlVirtualUnwind | 0x0 | 0x1800100b8 | 0x18968 | 0x16f68 | 0x426 |
UnhandledExceptionFilter | 0x0 | 0x1800100c0 | 0x18970 | 0x16f70 | 0x4e2 |
SetUnhandledExceptionFilter | 0x0 | 0x1800100c8 | 0x18978 | 0x16f78 | 0x4b3 |
SetLastError | 0x0 | 0x1800100d0 | 0x18980 | 0x16f80 | 0x480 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x1800100d8 | 0x18988 | 0x16f88 | 0x2eb |
Sleep | 0x0 | 0x1800100e0 | 0x18990 | 0x16f90 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x1800100e8 | 0x18998 | 0x16f98 | 0x1c6 |
TerminateProcess | 0x0 | 0x1800100f0 | 0x189a0 | 0x16fa0 | 0x4ce |
TlsAlloc | 0x0 | 0x1800100f8 | 0x189a8 | 0x16fa8 | 0x4d3 |
TlsGetValue | 0x0 | 0x180010100 | 0x189b0 | 0x16fb0 | 0x4d5 |
TlsSetValue | 0x0 | 0x180010108 | 0x189b8 | 0x16fb8 | 0x4d6 |
TlsFree | 0x0 | 0x180010110 | 0x189c0 | 0x16fc0 | 0x4d4 |
GetStartupInfoW | 0x0 | 0x180010118 | 0x189c8 | 0x16fc8 | 0x26a |
GetModuleHandleW | 0x0 | 0x180010120 | 0x189d0 | 0x16fd0 | 0x21e |
GetStdHandle | 0x0 | 0x180010128 | 0x189d8 | 0x16fd8 | 0x26b |
WriteFile | 0x0 | 0x180010130 | 0x189e0 | 0x16fe0 | 0x534 |
GetModuleFileNameW | 0x0 | 0x180010138 | 0x189e8 | 0x16fe8 | 0x21a |
LoadLibraryExW | 0x0 | 0x180010140 | 0x189f0 | 0x16ff0 | 0x340 |
IsValidCodePage | 0x0 | 0x180010148 | 0x189f8 | 0x16ff8 | 0x30c |
GetACP | 0x0 | 0x180010150 | 0x18a00 | 0x17000 | 0x16e |
GetOEMCP | 0x0 | 0x180010158 | 0x18a08 | 0x17008 | 0x23e |
GetCPInfo | 0x0 | 0x180010160 | 0x18a10 | 0x17010 | 0x178 |
HeapAlloc | 0x0 | 0x180010168 | 0x18a18 | 0x17018 | 0x2d3 |
GetProcessHeap | 0x0 | 0x180010170 | 0x18a20 | 0x17020 | 0x251 |
GetFileType | 0x0 | 0x180010178 | 0x18a28 | 0x17028 | 0x1fa |
GetModuleFileNameA | 0x0 | 0x180010180 | 0x18a30 | 0x17030 | 0x219 |
QueryPerformanceCounter | 0x0 | 0x180010188 | 0x18a38 | 0x17038 | 0x3a9 |
GetCurrentProcessId | 0x0 | 0x180010190 | 0x18a40 | 0x17040 | 0x1c7 |
GetSystemTimeAsFileTime | 0x0 | 0x180010198 | 0x18a48 | 0x17048 | 0x280 |
GetEnvironmentStringsW | 0x0 | 0x1800101a0 | 0x18a50 | 0x17050 | 0x1e1 |
FreeEnvironmentStringsW | 0x0 | 0x1800101a8 | 0x18a58 | 0x17058 | 0x167 |
HeapReAlloc | 0x0 | 0x1800101b0 | 0x18a60 | 0x17060 | 0x2da |
LCMapStringW | 0x0 | 0x1800101b8 | 0x18a68 | 0x17068 | 0x32f |
OutputDebugStringW | 0x0 | 0x1800101c0 | 0x18a70 | 0x17070 | 0x38c |
GetStringTypeW | 0x0 | 0x1800101c8 | 0x18a78 | 0x17078 | 0x270 |
FlushFileBuffers | 0x0 | 0x1800101d0 | 0x18a80 | 0x17080 | 0x15d |
GetConsoleCP | 0x0 | 0x1800101d8 | 0x18a88 | 0x17088 | 0x1a0 |
GetConsoleMode | 0x0 | 0x1800101e0 | 0x18a90 | 0x17090 | 0x1b2 |
SetStdHandle | 0x0 | 0x1800101e8 | 0x18a98 | 0x17098 | 0x494 |
SetFilePointerEx | 0x0 | 0x1800101f0 | 0x18aa0 | 0x170a0 | 0x475 |
WriteConsoleW | 0x0 | 0x1800101f8 | 0x18aa8 | 0x170a8 | 0x533 |
CloseHandle | 0x0 | 0x180010200 | 0x18ab0 | 0x170b0 | 0x52 |
CreateFileW | 0x0 | 0x180010208 | 0x18ab8 | 0x170b8 | 0x8f |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ursu.519232 |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\888.vbs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.-04ZPMvJi6.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.1m6dIgySWGmoF7.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.2Sg.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.5eu_PQV7HlM.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.5e_JRvSV j0o5CvfvuB.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.5JYGXqy7i-3.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.5sRGYdp9CY.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.74zzB6Qk8X1ShV g.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.7O4HPm13SlNjiylHK.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.Ajl369ZUr.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.BX16FqzPBPWPdZKTQ.ppt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.CAHNRsDoKqYgEJs1u.mkv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.CfmvmVTS.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.G-HjzbVnmspfm2f.ots | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.g89xx1751xuB.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.hZeyo2-.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.l-eDQFZ.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.lU w.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.O5 SWUg.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.oZuhPY6Jjtuxpg.ots | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.p4Thpqipn7OUYMXVVn.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.PT UjDG3AxT65B.avi | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.u-PQ3yrBp8ahgeH.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.x3 s4.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.-jofTXhuSI8aEDy.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.1XKYkeQtdp.mkv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.5J-YmGH 0.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.8mKFaI35uSK1LtwAdqme.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.E7vAZZ4eccaOUE9.swf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.EB5rLXOd WNo8nJAA.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.ElSWSoDryWv vp.flv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Gf_XCek78JFON1OFE.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.hutO74bx85O.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.IA9sw7U7.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.ib3D_IjKT.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Mo8fj6a0EqXM_47I_r0h.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.nTro10FkbVqY.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.NUxV.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.O8ECLmz.flv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.O98m.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.qWNW.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.rh_IeNS9bMX6K.ppt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.rqHOltOkJ3VXhPXIYc.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.uHbXh6ADbeocAE7.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Vlt9.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.WNdq e_WomB.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.XFI3dhzI.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.XhoPySH.flv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.XRqgvE5OSzKOHY.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.y7pJNN3pG_A0j QDzF6P.flv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Y9bGegNE7rAdchs.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.YHjLv4Tt.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.YNbrWBpd8p7Gx2jI84.avi | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.ZL_ut.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Local/Lock.GDIPFONTCACHEV1.DAT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Local/Lock.IconCache.db | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.3OynEeTqDiMMVkcwDAB.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.aEkp_wlE7x-.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.CbvGdid6xUt.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.OLR1Wef.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.U0_lZCZ2HLJcliK6Pu.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.wi5FFDGr.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.Wy857Yo_SIgVK.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.BUXxUXRQTvWQBJ.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.fFLjziW-aI6sa1zl4OT.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.YwxdQSzjs9.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.wRY2M7blf.mkv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.0aUHvQU5TQP9.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.45uKgufYvILt2vJRZV.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.AmKVElY_.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.Cq5uyYILvgxOupyOEp.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.CUyuW1.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.D2HRCLMHvG8vsoVn4O.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.e7gNZdR8Xpm4boI0c.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.eDAPud.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.FHte.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.FIWTmP6qHnpRbj4R.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.GKhCmGk4O.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.gRgJT-LoxgWnW9oc.ots | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.IxKmB9.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.kyujsI8JXUfKdP7Pnt.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.mQpYbIIZbdeK.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.n2f3JRF2i.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.p-0uXvZu.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.P0fUL_SWoQ4J.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.sNAPduGDpt_gL.pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.TC0U9NKWQmLwcKT9Tm.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.tYaTjI2KS54x1n0.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.uaGND5woOTB177za5y_.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.VbLadFS.ppt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.VJji3zvz.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.vVwim_.ppt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.X1aK yxHR96ZvbYsp.xls | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.yHCwRrDEIlN3K H_s.xlsx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Videos/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.Outlook Files | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\start menu\programs\startup\microcop.lnk | Dropped File | Shortcut |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\autCBC8.tmp | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.Angry Lola Loud Ran$omware.exe | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.2TOqqPIq5ZG.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.34ooK.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.Eahu5SI_RGHahaq_X.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.XfoiV1FdS.pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Documents/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»