VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Backdoor
Ransomware
Dropper
|
Threat Names: |
Ryuk
Trojan.GenericKD.32960184
Generic.Ransom.Ryuk3.0185DA67
...
|
udaryi.exe
Windows Exe (x86-32)
Created at 2020-01-18T11:03:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "21 minutes, 22 seconds" to "5 minutes, 50 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\udaryi.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401c1e |
Size Of Code | 0xb000 |
Size Of Initialized Data | 0x44200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-14 17:14:18+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xae87 | 0xb000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.61 |
.rdata | 0x40c000 | 0x581a | 0x5a00 | 0xb400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.82 |
.data | 0x412000 | 0x3d5ac | 0x3cc00 | 0x10e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.24 |
.gfids | 0x450000 | 0xac | 0x200 | 0x4da00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.4 |
.reloc | 0x451000 | 0xe08 | 0x1000 | 0x4dc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.15 |
Imports (3)
»
NETAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareAdd | 0x0 | 0x40c120 | 0x1129c | 0x1069c | 0xea |
KERNEL32.dll (71)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | 0x0 | 0x40c000 | 0x1117c | 0x1057c | 0x213 |
DecodePointer | 0x0 | 0x40c004 | 0x11180 | 0x10580 | 0xca |
GetLogicalDrives | 0x0 | 0x40c008 | 0x11184 | 0x10584 | 0x209 |
SetLastError | 0x0 | 0x40c00c | 0x11188 | 0x10588 | 0x473 |
GetCommandLineW | 0x0 | 0x40c010 | 0x1118c | 0x1058c | 0x187 |
GetCurrentProcess | 0x0 | 0x40c014 | 0x11190 | 0x10590 | 0x1c0 |
WriteFile | 0x0 | 0x40c018 | 0x11194 | 0x10594 | 0x525 |
GetModuleFileNameW | 0x0 | 0x40c01c | 0x11198 | 0x10598 | 0x214 |
CreateFileW | 0x0 | 0x40c020 | 0x1119c | 0x1059c | 0x8f |
GetVersionExW | 0x0 | 0x40c024 | 0x111a0 | 0x105a0 | 0x2a4 |
Sleep | 0x0 | 0x40c028 | 0x111a4 | 0x105a4 | 0x4b2 |
GetLastError | 0x0 | 0x40c02c | 0x111a8 | 0x105a8 | 0x202 |
LoadLibraryA | 0x0 | 0x40c030 | 0x111ac | 0x105ac | 0x33c |
CloseHandle | 0x0 | 0x40c034 | 0x111b0 | 0x105b0 | 0x52 |
GetWindowsDirectoryW | 0x0 | 0x40c038 | 0x111b4 | 0x105b4 | 0x2af |
GetProcAddress | 0x0 | 0x40c03c | 0x111b8 | 0x105b8 | 0x245 |
LocalFree | 0x0 | 0x40c040 | 0x111bc | 0x105bc | 0x348 |
FreeLibrary | 0x0 | 0x40c044 | 0x111c0 | 0x105c0 | 0x162 |
GetTickCount | 0x0 | 0x40c048 | 0x111c4 | 0x105c4 | 0x293 |
WriteConsoleW | 0x0 | 0x40c04c | 0x111c8 | 0x105c8 | 0x524 |
SetFilePointerEx | 0x0 | 0x40c050 | 0x111cc | 0x105cc | 0x467 |
QueryPerformanceCounter | 0x0 | 0x40c054 | 0x111d0 | 0x105d0 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x40c058 | 0x111d4 | 0x105d4 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x40c05c | 0x111d8 | 0x105d8 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x40c060 | 0x111dc | 0x105dc | 0x279 |
InitializeSListHead | 0x0 | 0x40c064 | 0x111e0 | 0x105e0 | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x40c068 | 0x111e4 | 0x105e4 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x40c06c | 0x111e8 | 0x105e8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x40c070 | 0x111ec | 0x105ec | 0x4a5 |
GetStartupInfoW | 0x0 | 0x40c074 | 0x111f0 | 0x105f0 | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x40c078 | 0x111f4 | 0x105f4 | 0x304 |
GetModuleHandleW | 0x0 | 0x40c07c | 0x111f8 | 0x105f8 | 0x218 |
TerminateProcess | 0x0 | 0x40c080 | 0x111fc | 0x105fc | 0x4c0 |
RtlUnwind | 0x0 | 0x40c084 | 0x11200 | 0x10600 | 0x418 |
EnterCriticalSection | 0x0 | 0x40c088 | 0x11204 | 0x10604 | 0xee |
LeaveCriticalSection | 0x0 | 0x40c08c | 0x11208 | 0x10608 | 0x339 |
DeleteCriticalSection | 0x0 | 0x40c090 | 0x1120c | 0x1060c | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c094 | 0x11210 | 0x10610 | 0x2e3 |
TlsAlloc | 0x0 | 0x40c098 | 0x11214 | 0x10614 | 0x4c5 |
TlsGetValue | 0x0 | 0x40c09c | 0x11218 | 0x10618 | 0x4c7 |
TlsSetValue | 0x0 | 0x40c0a0 | 0x1121c | 0x1061c | 0x4c8 |
TlsFree | 0x0 | 0x40c0a4 | 0x11220 | 0x10620 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x40c0a8 | 0x11224 | 0x10624 | 0x33e |
GetStdHandle | 0x0 | 0x40c0ac | 0x11228 | 0x10628 | 0x264 |
RaiseException | 0x0 | 0x40c0b0 | 0x1122c | 0x1062c | 0x3b1 |
MultiByteToWideChar | 0x0 | 0x40c0b4 | 0x11230 | 0x10630 | 0x367 |
WideCharToMultiByte | 0x0 | 0x40c0b8 | 0x11234 | 0x10634 | 0x511 |
ExitProcess | 0x0 | 0x40c0bc | 0x11238 | 0x10638 | 0x119 |
GetModuleHandleExW | 0x0 | 0x40c0c0 | 0x1123c | 0x1063c | 0x217 |
GetACP | 0x0 | 0x40c0c4 | 0x11240 | 0x10640 | 0x168 |
HeapFree | 0x0 | 0x40c0c8 | 0x11244 | 0x10644 | 0x2cf |
HeapAlloc | 0x0 | 0x40c0cc | 0x11248 | 0x10648 | 0x2cb |
FindClose | 0x0 | 0x40c0d0 | 0x1124c | 0x1064c | 0x12e |
FindFirstFileExA | 0x0 | 0x40c0d4 | 0x11250 | 0x10650 | 0x133 |
FindNextFileA | 0x0 | 0x40c0d8 | 0x11254 | 0x10654 | 0x143 |
IsValidCodePage | 0x0 | 0x40c0dc | 0x11258 | 0x10658 | 0x30a |
GetOEMCP | 0x0 | 0x40c0e0 | 0x1125c | 0x1065c | 0x237 |
GetCPInfo | 0x0 | 0x40c0e4 | 0x11260 | 0x10660 | 0x172 |
GetCommandLineA | 0x0 | 0x40c0e8 | 0x11264 | 0x10664 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x40c0ec | 0x11268 | 0x10668 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x40c0f0 | 0x1126c | 0x1066c | 0x161 |
LCMapStringW | 0x0 | 0x40c0f4 | 0x11270 | 0x10670 | 0x32d |
SetStdHandle | 0x0 | 0x40c0f8 | 0x11274 | 0x10674 | 0x487 |
GetFileType | 0x0 | 0x40c0fc | 0x11278 | 0x10678 | 0x1f3 |
GetStringTypeW | 0x0 | 0x40c100 | 0x1127c | 0x1067c | 0x269 |
GetProcessHeap | 0x0 | 0x40c104 | 0x11280 | 0x10680 | 0x24a |
HeapSize | 0x0 | 0x40c108 | 0x11284 | 0x10684 | 0x2d4 |
HeapReAlloc | 0x0 | 0x40c10c | 0x11288 | 0x10688 | 0x2d2 |
FlushFileBuffers | 0x0 | 0x40c110 | 0x1128c | 0x1068c | 0x157 |
GetConsoleCP | 0x0 | 0x40c114 | 0x11290 | 0x10690 | 0x19a |
GetConsoleMode | 0x0 | 0x40c118 | 0x11294 | 0x10694 | 0x1ac |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x40c128 | 0x112a4 | 0x106a4 | 0x122 |
CommandLineToArgvW | 0x0 | 0x40c12c | 0x112a8 | 0x106a8 | 0x6 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
udaryi.exe | 1 | 0x002B0000 | 0x00301FFF | Relevant Image |
![]() |
32-bit | 0x002B21B0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02810000 | 0x02810FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
udaryi.exe | 1 | 0x002B0000 | 0x00301FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32960184 |
Malicious
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\SharedDataEvents.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeSysFnt10.lst.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Adobe\Acrobat\10.0\AdobeCMapFnt10.lst.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Adobe\Acrobat\10.0\Cache\AcroFnt10.lst.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\ACECache11.lst.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wsRGB.icc.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wscRGB.icc.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\GDIPFONTCACHEV1.DAT.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\IconCache.db.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\-lr0Ch.doc.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\AdobeARM.log.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\6p47SKC0 jWuZ.mp3.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5z_ijfYGlkugL6.wav.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5hDsOAAkJpxZ1n.m4a.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\4XLcXlYhAvHImy-.bmp.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\4H2RiR0v1TTc.mp3.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\1o86XN.gif.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\9iFq8y63.mkv.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\A2rJ_R-Shn.pdf.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\b0qHL.odt.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\c2o-.png.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\cN7DcCnDgk9.gif.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\-jDCM.csv.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Cookies\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\dMinn1FcJBx.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\H3Njx34uqpIif.flv.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\KsZxIV-1Om7TALU.jpg.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\lqxKQ3ka3.mp3.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\LYl8hL0zcGiP.flv.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\O1d V02Bb-Yyjax.ppt.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\rUJZ.gif.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\s-gmsn.mkv.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\suL76PCDpBtAV.mp4.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Ta8_Kc.bmp.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History\Low\History.IE5\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Feeds Cache\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\FORMS\FRMCACHE.DAT.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.bak.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Media Player\LocalMLS_3.wmdb.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\Outlook.sharing.xml.obi.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Outlook\mapisvc.inf.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Visio\content14.dat.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Visio\thumbs.dat.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\edb.chk.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\oeold.xml.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\bears.jpg | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\garden.htm | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\garden.jpg | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\stars.htm | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\edb00001.log.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\stars.jpg | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\peacock.htm | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Media\12.0\WMSDKNS.XML.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Media\12.0\WMSDKNS.DTD.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\bears.htm | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\edbres00001.jrs.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\roses.htm | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\roses.jpg | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows mail\stationery\peacock.jpg | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\edb.log.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Mail\edbres00002.jrs.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\History\History.IE5\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\temp\9u 2rhdpu7bjqdhbanzn.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\jSvf1m3yElMB-Sbu17bn.mp4.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\aX8mAHttLRxPap-u.mp3.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\jEbUyuJue3PUfdTXjk.gif.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\qz-EhFMmP0nfJPHKxYa.mp3.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\cWKgRNKb-nRhISbFb.odp.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\nBP 6drY_iC njnK.wav.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\2bzGyA5wVpzpZK3I0Z6-.wav.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\tEz6zz54a3QKe1jYs.mp3.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\uJdarKwGlT5w5zNqc7M.jpg.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\uw8kRfAIZafm8JjQ.avi.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Y2djYuhT3xjlKZ3r.ppt.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\yLt4USz55bOIOOEbZn.wav.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\ylwNSYMrPkhmeWLV4xtt.mkv.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\_B66Lv3zO7vtubgGITA.odt.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Low\MSIMGSIZ.DAT.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History\Low\History.IE5\MSHist012017071220170713\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\feeds\microsoft feeds~\microsoft at home~.feed-ms | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\feeds\microsoft feeds~\microsoft at work~.feed-ms | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat.RYK | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\Documents and Settings\5p5NrGJn0jS HALPmcxz\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\frameiconcache.dat.RYK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\media player\currentdatabase_372.wmdb | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
HermesRyukEncryptedFile | File encrypted by Hermes or Ryuk Ransomware | Ransomware |
5/5
|
...
|
C:\users\Public\fMRKmiSrvlan.exe | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x140000000 |
Entry Point | 0x140007af8 |
Size Of Code | 0x11400 |
Size Of Initialized Data | 0x14d600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2020-01-14 17:14:11+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x113f0 | 0x11400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.46 |
.rdata | 0x140013000 | 0x9292 | 0x9400 | 0x11800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.76 |
.data | 0x14001d000 | 0x142700 | 0x4c00 | 0x1ac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.14 |
.pdata | 0x140160000 | 0xed0 | 0x1000 | 0x1f800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.69 |
.gfids | 0x140161000 | 0xbc | 0x200 | 0x20800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.49 |
.reloc | 0x140162000 | 0x638 | 0x800 | 0x20a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.82 |
Imports (2)
»
KERNEL32.dll (81)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalFree | 0x0 | 0x140013000 | 0x1b9d0 | 0x1a1d0 | 0x34a |
HeapAlloc | 0x0 | 0x140013008 | 0x1b9d8 | 0x1a1d8 | 0x2d3 |
HeapFree | 0x0 | 0x140013010 | 0x1b9e0 | 0x1a1e0 | 0x2d7 |
GetProcessHeap | 0x0 | 0x140013018 | 0x1b9e8 | 0x1a1e8 | 0x251 |
GetBinaryTypeW | 0x0 | 0x140013020 | 0x1b9f0 | 0x1a1f0 | 0x177 |
OpenProcess | 0x0 | 0x140013028 | 0x1b9f8 | 0x1a1f8 | 0x382 |
GetCurrentProcess | 0x0 | 0x140013030 | 0x1ba00 | 0x1a200 | 0x1c6 |
ExitProcess | 0x0 | 0x140013038 | 0x1ba08 | 0x1a208 | 0x11f |
GetCurrentThread | 0x0 | 0x140013040 | 0x1ba10 | 0x1a210 | 0x1ca |
SetLastError | 0x0 | 0x140013048 | 0x1ba18 | 0x1a218 | 0x480 |
Sleep | 0x0 | 0x140013050 | 0x1ba20 | 0x1a220 | 0x4c0 |
GlobalFree | 0x0 | 0x140013058 | 0x1ba28 | 0x1a228 | 0x2c2 |
LoadLibraryA | 0x0 | 0x140013060 | 0x1ba30 | 0x1a230 | 0x33e |
GetCommandLineW | 0x0 | 0x140013068 | 0x1ba38 | 0x1a238 | 0x18d |
GetTempPathW | 0x0 | 0x140013070 | 0x1ba40 | 0x1a240 | 0x28c |
GetVersionExW | 0x0 | 0x140013078 | 0x1ba48 | 0x1a248 | 0x2ac |
IsWow64Process | 0x0 | 0x140013080 | 0x1ba50 | 0x1a250 | 0x310 |
CreateToolhelp32Snapshot | 0x0 | 0x140013088 | 0x1ba58 | 0x1a258 | 0xbd |
Process32FirstW | 0x0 | 0x140013090 | 0x1ba60 | 0x1a260 | 0x398 |
Process32NextW | 0x0 | 0x140013098 | 0x1ba68 | 0x1a268 | 0x39a |
GlobalAlloc | 0x0 | 0x1400130a0 | 0x1ba70 | 0x1a270 | 0x2bb |
GetProcAddress | 0x0 | 0x1400130a8 | 0x1ba78 | 0x1a278 | 0x24c |
WinExec | 0x0 | 0x1400130b0 | 0x1ba80 | 0x1a280 | 0x521 |
FreeLibrary | 0x0 | 0x1400130b8 | 0x1ba88 | 0x1a288 | 0x168 |
WriteConsoleW | 0x0 | 0x1400130c0 | 0x1ba90 | 0x1a290 | 0x533 |
SetFilePointerEx | 0x0 | 0x1400130c8 | 0x1ba98 | 0x1a298 | 0x475 |
GetConsoleMode | 0x0 | 0x1400130d0 | 0x1baa0 | 0x1a2a0 | 0x1b2 |
GetConsoleCP | 0x0 | 0x1400130d8 | 0x1baa8 | 0x1a2a8 | 0x1a0 |
FlushFileBuffers | 0x0 | 0x1400130e0 | 0x1bab0 | 0x1a2b0 | 0x15d |
HeapReAlloc | 0x0 | 0x1400130e8 | 0x1bab8 | 0x1a2b8 | 0x2da |
HeapSize | 0x0 | 0x1400130f0 | 0x1bac0 | 0x1a2c0 | 0x2dc |
GetFileType | 0x0 | 0x1400130f8 | 0x1bac8 | 0x1a2c8 | 0x1fa |
SetStdHandle | 0x0 | 0x140013100 | 0x1bad0 | 0x1a2d0 | 0x494 |
QueryPerformanceCounter | 0x0 | 0x140013108 | 0x1bad8 | 0x1a2d8 | 0x3a9 |
GetCurrentProcessId | 0x0 | 0x140013110 | 0x1bae0 | 0x1a2e0 | 0x1c7 |
GetCurrentThreadId | 0x0 | 0x140013118 | 0x1bae8 | 0x1a2e8 | 0x1cb |
GetSystemTimeAsFileTime | 0x0 | 0x140013120 | 0x1baf0 | 0x1a2f0 | 0x280 |
InitializeSListHead | 0x0 | 0x140013128 | 0x1baf8 | 0x1a2f8 | 0x2ef |
RtlCaptureContext | 0x0 | 0x140013130 | 0x1bb00 | 0x1a300 | 0x418 |
RtlLookupFunctionEntry | 0x0 | 0x140013138 | 0x1bb08 | 0x1a308 | 0x41f |
RtlVirtualUnwind | 0x0 | 0x140013140 | 0x1bb10 | 0x1a310 | 0x426 |
IsDebuggerPresent | 0x0 | 0x140013148 | 0x1bb18 | 0x1a318 | 0x302 |
UnhandledExceptionFilter | 0x0 | 0x140013150 | 0x1bb20 | 0x1a320 | 0x4e2 |
SetUnhandledExceptionFilter | 0x0 | 0x140013158 | 0x1bb28 | 0x1a328 | 0x4b3 |
GetStartupInfoW | 0x0 | 0x140013160 | 0x1bb30 | 0x1a330 | 0x26a |
IsProcessorFeaturePresent | 0x0 | 0x140013168 | 0x1bb38 | 0x1a338 | 0x306 |
GetModuleHandleW | 0x0 | 0x140013170 | 0x1bb40 | 0x1a340 | 0x21e |
RtlUnwindEx | 0x0 | 0x140013178 | 0x1bb48 | 0x1a348 | 0x425 |
RtlPcToFileHeader | 0x0 | 0x140013180 | 0x1bb50 | 0x1a350 | 0x421 |
RaiseException | 0x0 | 0x140013188 | 0x1bb58 | 0x1a358 | 0x3b4 |
GetLastError | 0x0 | 0x140013190 | 0x1bb60 | 0x1a360 | 0x208 |
EnterCriticalSection | 0x0 | 0x140013198 | 0x1bb68 | 0x1a368 | 0xf2 |
LeaveCriticalSection | 0x0 | 0x1400131a0 | 0x1bb70 | 0x1a370 | 0x33b |
DeleteCriticalSection | 0x0 | 0x1400131a8 | 0x1bb78 | 0x1a378 | 0xd2 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x1400131b0 | 0x1bb80 | 0x1a380 | 0x2eb |
TlsAlloc | 0x0 | 0x1400131b8 | 0x1bb88 | 0x1a388 | 0x4d3 |
TlsGetValue | 0x0 | 0x1400131c0 | 0x1bb90 | 0x1a390 | 0x4d5 |
TlsSetValue | 0x0 | 0x1400131c8 | 0x1bb98 | 0x1a398 | 0x4d6 |
TlsFree | 0x0 | 0x1400131d0 | 0x1bba0 | 0x1a3a0 | 0x4d4 |
LoadLibraryExW | 0x0 | 0x1400131d8 | 0x1bba8 | 0x1a3a8 | 0x340 |
TerminateProcess | 0x0 | 0x1400131e0 | 0x1bbb0 | 0x1a3b0 | 0x4ce |
GetModuleHandleExW | 0x0 | 0x1400131e8 | 0x1bbb8 | 0x1a3b8 | 0x21d |
GetStdHandle | 0x0 | 0x1400131f0 | 0x1bbc0 | 0x1a3c0 | 0x26b |
WriteFile | 0x0 | 0x1400131f8 | 0x1bbc8 | 0x1a3c8 | 0x534 |
GetModuleFileNameW | 0x0 | 0x140013200 | 0x1bbd0 | 0x1a3d0 | 0x21a |
MultiByteToWideChar | 0x0 | 0x140013208 | 0x1bbd8 | 0x1a3d8 | 0x369 |
WideCharToMultiByte | 0x0 | 0x140013210 | 0x1bbe0 | 0x1a3e0 | 0x520 |
GetACP | 0x0 | 0x140013218 | 0x1bbe8 | 0x1a3e8 | 0x16e |
GetStringTypeW | 0x0 | 0x140013220 | 0x1bbf0 | 0x1a3f0 | 0x270 |
LCMapStringW | 0x0 | 0x140013228 | 0x1bbf8 | 0x1a3f8 | 0x32f |
CloseHandle | 0x0 | 0x140013230 | 0x1bc00 | 0x1a400 | 0x52 |
FindClose | 0x0 | 0x140013238 | 0x1bc08 | 0x1a408 | 0x134 |
FindFirstFileExW | 0x0 | 0x140013240 | 0x1bc10 | 0x1a410 | 0x13a |
FindNextFileW | 0x0 | 0x140013248 | 0x1bc18 | 0x1a418 | 0x14b |
IsValidCodePage | 0x0 | 0x140013250 | 0x1bc20 | 0x1a420 | 0x30c |
GetOEMCP | 0x0 | 0x140013258 | 0x1bc28 | 0x1a428 | 0x23e |
GetCPInfo | 0x0 | 0x140013260 | 0x1bc30 | 0x1a430 | 0x178 |
GetCommandLineA | 0x0 | 0x140013268 | 0x1bc38 | 0x1a438 | 0x18c |
GetEnvironmentStringsW | 0x0 | 0x140013270 | 0x1bc40 | 0x1a440 | 0x1e1 |
FreeEnvironmentStringsW | 0x0 | 0x140013278 | 0x1bc48 | 0x1a448 | 0x167 |
CreateFileW | 0x0 | 0x140013280 | 0x1bc50 | 0x1a450 | 0x8f |
WS2_32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x140013290 | 0x1bc60 | 0x1a460 | - |
WSAStartup | 0x73 | 0x140013298 | 0x1bc68 | 0x1a468 | - |
socket | 0x17 | 0x1400132a0 | 0x1bc70 | 0x1a470 | - |
setsockopt | 0x15 | 0x1400132a8 | 0x1bc78 | 0x1a478 | - |
sendto | 0x14 | 0x1400132b0 | 0x1bc80 | 0x1a480 | - |
inet_addr | 0xb | 0x1400132b8 | 0x1bc88 | 0x1a488 | - |
htons | 0x9 | 0x1400132c0 | 0x1bc90 | 0x1a490 | - |
htonl | 0x8 | 0x1400132c8 | 0x1bc98 | 0x1a498 | - |
closesocket | 0x3 | 0x1400132d0 | 0x1bca0 | 0x1a4a0 | - |
bind | 0x2 | 0x1400132d8 | 0x1bca8 | 0x1a4a8 | - |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
fmrkmisrvlan.exe | 3 | 0x13F9C0000 | 0x13FB22FFF | Relevant Image |
![]() |
64-bit | 0x13F9C8380 |
![]() |
![]() |
...
|
uzkoh.exe | 2 | 0x13F450000 | 0x13F5B2FFF | Final Dump |
![]() |
64-bit | 0x13F451844 |
![]() |
![]() |
...
|
fmrkmisrvlan.exe | 3 | 0x13F9C0000 | 0x13FB22FFF | Final Dump |
![]() |
64-bit | 0x13F9C268C |
![]() |
![]() |
...
|
buffer | 3 | 0x13F450000 | 0x13F5B2FFF | First Execution |
![]() |
64-bit | 0x13F457014 |
![]() |
![]() |
...
|
c:\programdata\microsoft\crypto\rsa\machinekeys\08e575673cce10c72090304839888e02_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Dropped File | Stream |
Unknown
|
...
|
»