VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.Ransom.AIG
|
one.exe
Windows Exe (x86-32)
Created 4 years ago
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\one.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41a670 |
Size Of Code | 0x2000 |
Size Of Initialized Data | 0x10000 |
Size Of Uninitialized Data | 0x18000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 18:49:03+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x18000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x419000 | 0x2000 | 0x1800 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.8 |
.rsrc | 0x41b000 | 0x10000 | 0x10000 | 0x1a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.36 |
Imports (7)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x42add4 | 0x2add4 | 0x117d4 | 0x0 |
GetProcAddress | 0x0 | 0x42add8 | 0x2add8 | 0x117d8 | 0x0 |
VirtualProtect | 0x0 | 0x42addc | 0x2addc | 0x117dc | 0x0 |
VirtualAlloc | 0x0 | 0x42ade0 | 0x2ade0 | 0x117e0 | 0x0 |
VirtualFree | 0x0 | 0x42ade4 | 0x2ade4 | 0x117e4 | 0x0 |
ExitProcess | 0x0 | 0x42ade8 | 0x2ade8 | 0x117e8 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x42adf0 | 0x2adf0 | 0x117f0 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x42adf8 | 0x2adf8 | 0x117f8 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontIndirectA | 0x0 | 0x42ae00 | 0x2ae00 | 0x11800 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x42ae08 | 0x2ae08 | 0x11808 | 0x0 |
shlwapi.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecA | 0x0 | 0x42ae10 | 0x2ae10 | 0x11810 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndPaint | 0x0 | 0x42ae18 | 0x2ae18 | 0x11818 | 0x0 |
Memory Dumps (12)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
one.exe | 1 | 0x00400000 | 0x0042AFFF | First Execution |
![]() |
32-bit | 0x0041A670 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x00401F87 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x00402604 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x0040138E |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004010AA |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004010AA |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Content Changed |
![]() |
32-bit | 0x00401736 |
![]() |
![]() |
...
|
one.exe | 1 | 0x00400000 | 0x0042AFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.AIG |
Malicious
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ESP\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\FRA\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\FRA\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HRV\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HRV\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HUN\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HUN\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ITA\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ITA\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\KOR\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\KOR\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NLD\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NLD\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NOR\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NOR\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUM\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUM\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUS\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUS\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SUO\AdobeID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SUO\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SVE\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SVE\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\TUR\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\TUR\DefaultID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\AdobeID.pdf.lockerxxs | Dropped File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\DefaultID.pdf | Modified File |
Suspicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.lockerxxs | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\FormsVersion1Warning.htm.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\FormsViewFrame.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\FormsViewTemplate.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\FormToolImages.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\ViewHeaderPreview.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsBlankPage.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsBrowserUpgrade.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsColorChart.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsFormTemplate.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsFormTemplateRTL.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsImageTemplate.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsMacroTemplate.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsPreviewTemplate.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsPreviewTemplateRTL.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsPrintTemplate.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\FormsPrintTemplateRTL.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms4\FormsViewAttachmentIcons.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveForms5\InfoPathWelcomeImage.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\BriefcaseIcon.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\CircleIcons.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\MeetingIcon.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\ProjectStatusIcons.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\ProjectTaskIcon.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\ProjectToolsetIconImages.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\SplashImage.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\TABOFF.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\TABON.JPG.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\WHITEBOX.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\GrooveProjectToolset\ZoomIcons.jpg.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\Groove\ToolData\groove.net\Welcome Tool\IconImages.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\JFONT.DAT.lockerxxs | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\LOOKUP.DAT | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\APPLAUSE.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\ARROW.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\BOMB.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\BREEZE.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\CAMERA.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\CASHREG.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\CHIMES.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\CLICK.WAV.lockerxxs | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\COIN.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ESP\AdobeID.pdf | Modified File |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CAT\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CHS\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CHT\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CZE\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DAN\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DEU\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ESP\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\EUQ\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\FRA\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HRV\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HUN\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ITA\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\JPN\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\KOR\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NLD\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NOR\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\PTB\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUM\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUS\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SKY\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SLV\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SUO\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SVE\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\TUR\license.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\UKR\license.html.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\benefits-4[1].jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\browser[1].htm | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\e4-190963-91cdfbc1[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\eula_text[1].htm.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\f[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\google_plus_16dp[1].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\index[1].htm.lockerxxs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\print[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ABV8L7MY\tecjslog[1].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AA3DGHW[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AA3e1pt[2].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AA42eYr[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AA61ILp[2].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AA6SNZ6[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAbyinC[1].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAicW5W[1].jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAj0doQ[1].jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAkqhIf[1].png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAmo09p[1].jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAmUyV2[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\AAn7gKR[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\activityi;src=2542116;type=clien612;cat=chrom0;ord=1;num=7814394060213[1].htm | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\BB5zDwX[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IKQEEPZR\BBaK3Nm[1].png.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.lockerxxs | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\BIN\1033\FPEXT.MSG.lockerxxs | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\DRUMROLL.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\EXPLODE.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\HAMMER.WAV.lockerxxs | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\LASER.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\PUSH.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\SUCTION.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\TYPE.WAV | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\VOLTAGE.WAV.lockerxxs | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\WHOOSH.WAV.lockerxxs | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office14\MEDIA\WIND.WAV.lockerxxs | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\HOW TO DECRYPT FILES.txt | Dropped File | Text |
Unknown
|
...
|
»