VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Spyware, Trojan |
Server.exe
Windows Exe (x86-32)
Created at 2019-07-07T11:30:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Server.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-06 18:46 (UTC+2) |
Last Seen | 2019-07-07 05:36 (UTC+2) |
Names | Win32.Trojan.Nebuler |
Families | Nebuler |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44b600 |
Size Of Code | 0x109800 |
Size Of Initialized Data | 0x1be00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Packer | PECompact 2.xx --> BitSum Technologies |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x26e000 | 0xc8000 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.rsrc | 0x66f000 | 0x1000 | 0x1000 | 0xc8200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.48 |
Imports (1)
»
kernel32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x66f130 | 0x26f130 | 0xc8330 | 0x0 |
GetProcAddress | 0x0 | 0x66f134 | 0x26f134 | 0xc8334 | 0x0 |
VirtualAlloc | 0x0 | 0x66f138 | 0x26f138 | 0xc8338 | 0x0 |
VirtualFree | 0x0 | 0x66f13c | 0x26f13c | 0xc833c | 0x0 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
server.exe | 1 | 0x00400000 | 0x0066FFFF | Content Changed | - | 32-bit | 0x0066FE7C, 0x0044B600 |
![]() |
![]() |
...
|
server.exe | 1 | 0x00400000 | 0x0066FFFF | Content Changed | - | 32-bit | 0x0044B616 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x00022FFF | First Execution | - | 32-bit | 0x00021084, 0x00020A8C |
![]() |
![]() |
...
|
server.exe | 1 | 0x00400000 | 0x0066FFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Nebuler.12 |
Malicious
|
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PptLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PubLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PubLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlkLR.cab | Modified File | Audio |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proof.en/Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proof.en/Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\/Boot\@ READ ME TO RECOVER FILES @.txt | Dropped File | Text |
Unknown
|
...
|
»