VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Ransom.Imps.1
Mal/Generic-S
|
svhost.exe
Windows Exe (x86-32)
Created at 2020-02-19T08:39:00
Remarks (1/1)
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\svhost.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x43a02c |
Size Of Code | 0x72a00 |
Size Of Initialized Data | 0x35800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-15 11:22:18+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x72896 | 0x72a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.54 |
.rdata | 0x474000 | 0x2ad42 | 0x2ae00 | 0x72e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.35 |
.data | 0x49f000 | 0x4b68 | 0x3a00 | 0x9dc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.78 |
.rsrc | 0x4a4000 | 0x1e0 | 0x200 | 0xa1600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x4a5000 | 0x5a70 | 0x5c00 | 0xa1800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.57 |
Imports (11)
»
KERNEL32.dll (138)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Process32NextW | 0x0 | 0x474078 | 0x9dc70 | 0x9ca70 | 0x42e |
Process32FirstW | 0x0 | 0x47407c | 0x9dc74 | 0x9ca74 | 0x42c |
CreateProcessW | 0x0 | 0x474080 | 0x9dc78 | 0x9ca78 | 0xe5 |
GetTickCount | 0x0 | 0x474084 | 0x9dc7c | 0x9ca7c | 0x307 |
CopyFileW | 0x0 | 0x474088 | 0x9dc80 | 0x9ca80 | 0xad |
GetCurrentProcess | 0x0 | 0x47408c | 0x9dc84 | 0x9ca84 | 0x217 |
WriteConsoleW | 0x0 | 0x474090 | 0x9dc88 | 0x9ca88 | 0x611 |
CreateToolhelp32Snapshot | 0x0 | 0x474094 | 0x9dc8c | 0x9ca8c | 0xfc |
OpenProcess | 0x0 | 0x474098 | 0x9dc90 | 0x9ca90 | 0x40d |
WaitForSingleObject | 0x0 | 0x47409c | 0x9dc94 | 0x9ca94 | 0x5d7 |
TerminateProcess | 0x0 | 0x4740a0 | 0x9dc98 | 0x9ca98 | 0x58c |
FindClose | 0x0 | 0x4740a4 | 0x9dc9c | 0x9ca9c | 0x175 |
FindNextVolumeW | 0x0 | 0x4740a8 | 0x9dca0 | 0x9caa0 | 0x191 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x4740ac | 0x9dca4 | 0x9caa4 | 0x324 |
FindVolumeClose | 0x0 | 0x4740b0 | 0x9dca8 | 0x9caa8 | 0x198 |
SetVolumeMountPointW | 0x0 | 0x4740b4 | 0x9dcac | 0x9caac | 0x574 |
FindFirstVolumeW | 0x0 | 0x4740b8 | 0x9dcb0 | 0x9cab0 | 0x186 |
QueryDosDeviceW | 0x0 | 0x4740bc | 0x9dcb4 | 0x9cab4 | 0x445 |
GetEnvironmentVariableW | 0x0 | 0x4740c0 | 0x9dcb8 | 0x9cab8 | 0x239 |
GetLogicalDrives | 0x0 | 0x4740c4 | 0x9dcbc | 0x9cabc | 0x268 |
GetProcessHeap | 0x0 | 0x4740c8 | 0x9dcc0 | 0x9cac0 | 0x2b4 |
MoveFileExW | 0x0 | 0x4740cc | 0x9dcc4 | 0x9cac4 | 0x3e8 |
SetFilePointerEx | 0x0 | 0x4740d0 | 0x9dcc8 | 0x9cac8 | 0x523 |
HeapAlloc | 0x0 | 0x4740d4 | 0x9dccc | 0x9cacc | 0x345 |
CloseHandle | 0x0 | 0x4740d8 | 0x9dcd0 | 0x9cad0 | 0x86 |
GetLastError | 0x0 | 0x4740dc | 0x9dcd4 | 0x9cad4 | 0x261 |
SetFileAttributesW | 0x0 | 0x4740e0 | 0x9dcd8 | 0x9cad8 | 0x51d |
GetFileAttributesW | 0x0 | 0x4740e4 | 0x9dcdc | 0x9cadc | 0x245 |
CreateFileW | 0x0 | 0x4740e8 | 0x9dce0 | 0x9cae0 | 0xcb |
WriteFile | 0x0 | 0x4740ec | 0x9dce4 | 0x9cae4 | 0x612 |
HeapSize | 0x0 | 0x4740f0 | 0x9dce8 | 0x9cae8 | 0x34e |
GetConsoleMode | 0x0 | 0x4740f4 | 0x9dcec | 0x9caec | 0x1fc |
GetConsoleCP | 0x0 | 0x4740f8 | 0x9dcf0 | 0x9caf0 | 0x1ea |
FlushFileBuffers | 0x0 | 0x4740fc | 0x9dcf4 | 0x9caf4 | 0x19f |
SetStdHandle | 0x0 | 0x474100 | 0x9dcf8 | 0x9caf8 | 0x54a |
FreeEnvironmentStringsW | 0x0 | 0x474104 | 0x9dcfc | 0x9cafc | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x474108 | 0x9dd00 | 0x9cb00 | 0x237 |
GetCommandLineW | 0x0 | 0x47410c | 0x9dd04 | 0x9cb04 | 0x1d7 |
GetCommandLineA | 0x0 | 0x474110 | 0x9dd08 | 0x9cb08 | 0x1d6 |
GetOEMCP | 0x0 | 0x474114 | 0x9dd0c | 0x9cb0c | 0x297 |
GetACP | 0x0 | 0x474118 | 0x9dd10 | 0x9cb10 | 0x1b2 |
IsValidCodePage | 0x0 | 0x47411c | 0x9dd14 | 0x9cb14 | 0x38b |
HeapReAlloc | 0x0 | 0x474120 | 0x9dd18 | 0x9cb18 | 0x34c |
GetFileType | 0x0 | 0x474124 | 0x9dd1c | 0x9cb1c | 0x24e |
GetTimeZoneInformation | 0x0 | 0x474128 | 0x9dd20 | 0x9cb20 | 0x30e |
EnumSystemLocalesW | 0x0 | 0x47412c | 0x9dd24 | 0x9cb24 | 0x154 |
HeapFree | 0x0 | 0x474130 | 0x9dd28 | 0x9cb28 | 0x349 |
GetFileSizeEx | 0x0 | 0x474134 | 0x9dd2c | 0x9cb2c | 0x24c |
GetUserDefaultLCID | 0x0 | 0x474138 | 0x9dd30 | 0x9cb30 | 0x312 |
IsValidLocale | 0x0 | 0x47413c | 0x9dd34 | 0x9cb34 | 0x38d |
GetTimeFormatW | 0x0 | 0x474140 | 0x9dd38 | 0x9cb38 | 0x30c |
GetDateFormatW | 0x0 | 0x474144 | 0x9dd3c | 0x9cb3c | 0x221 |
GetStdHandle | 0x0 | 0x474148 | 0x9dd40 | 0x9cb40 | 0x2d2 |
ReadFile | 0x0 | 0x47414c | 0x9dd44 | 0x9cb44 | 0x473 |
OpenMutexW | 0x0 | 0x474150 | 0x9dd48 | 0x9cb48 | 0x409 |
Sleep | 0x0 | 0x474154 | 0x9dd4c | 0x9cb4c | 0x57d |
CreateMutexW | 0x0 | 0x474158 | 0x9dd50 | 0x9cb50 | 0xda |
GetModuleFileNameW | 0x0 | 0x47415c | 0x9dd54 | 0x9cb54 | 0x274 |
SetEnvironmentVariableW | 0x0 | 0x474160 | 0x9dd58 | 0x9cb58 | 0x514 |
EncodePointer | 0x0 | 0x474164 | 0x9dd5c | 0x9cb5c | 0x12d |
DecodePointer | 0x0 | 0x474168 | 0x9dd60 | 0x9cb60 | 0x109 |
RaiseException | 0x0 | 0x47416c | 0x9dd64 | 0x9cb64 | 0x462 |
GetCurrentThreadId | 0x0 | 0x474170 | 0x9dd68 | 0x9cb68 | 0x21c |
IsProcessorFeaturePresent | 0x0 | 0x474174 | 0x9dd6c | 0x9cb6c | 0x386 |
QueueUserWorkItem | 0x0 | 0x474178 | 0x9dd70 | 0x9cb70 | 0x457 |
GetModuleHandleExW | 0x0 | 0x47417c | 0x9dd74 | 0x9cb74 | 0x277 |
EnterCriticalSection | 0x0 | 0x474180 | 0x9dd78 | 0x9cb78 | 0x131 |
LeaveCriticalSection | 0x0 | 0x474184 | 0x9dd7c | 0x9cb7c | 0x3bd |
TryEnterCriticalSection | 0x0 | 0x474188 | 0x9dd80 | 0x9cb80 | 0x5a7 |
DeleteCriticalSection | 0x0 | 0x47418c | 0x9dd84 | 0x9cb84 | 0x110 |
QueryPerformanceCounter | 0x0 | 0x474190 | 0x9dd88 | 0x9cb88 | 0x44d |
QueryPerformanceFrequency | 0x0 | 0x474194 | 0x9dd8c | 0x9cb8c | 0x44e |
FormatMessageW | 0x0 | 0x474198 | 0x9dd90 | 0x9cb90 | 0x1a7 |
WideCharToMultiByte | 0x0 | 0x47419c | 0x9dd94 | 0x9cb94 | 0x5fe |
MultiByteToWideChar | 0x0 | 0x4741a0 | 0x9dd98 | 0x9cb98 | 0x3ef |
FindFirstFileExW | 0x0 | 0x4741a4 | 0x9dd9c | 0x9cb9c | 0x17b |
FindNextFileW | 0x0 | 0x4741a8 | 0x9dda0 | 0x9cba0 | 0x18c |
GetFileAttributesExW | 0x0 | 0x4741ac | 0x9dda4 | 0x9cba4 | 0x242 |
SetLastError | 0x0 | 0x4741b0 | 0x9dda8 | 0x9cba8 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4741b4 | 0x9ddac | 0x9cbac | 0x35f |
CreateEventW | 0x0 | 0x4741b8 | 0x9ddb0 | 0x9cbb0 | 0xbf |
SwitchToThread | 0x0 | 0x4741bc | 0x9ddb4 | 0x9cbb4 | 0x587 |
TlsAlloc | 0x0 | 0x4741c0 | 0x9ddb8 | 0x9cbb8 | 0x59e |
TlsGetValue | 0x0 | 0x4741c4 | 0x9ddbc | 0x9cbbc | 0x5a0 |
TlsSetValue | 0x0 | 0x4741c8 | 0x9ddc0 | 0x9cbc0 | 0x5a1 |
TlsFree | 0x0 | 0x4741cc | 0x9ddc4 | 0x9cbc4 | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x4741d0 | 0x9ddc8 | 0x9cbc8 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x4741d4 | 0x9ddcc | 0x9cbcc | 0x278 |
GetProcAddress | 0x0 | 0x4741d8 | 0x9ddd0 | 0x9cbd0 | 0x2ae |
WaitForSingleObjectEx | 0x0 | 0x4741dc | 0x9ddd4 | 0x9cbd4 | 0x5d8 |
GetStringTypeW | 0x0 | 0x4741e0 | 0x9ddd8 | 0x9cbd8 | 0x2d7 |
CompareStringW | 0x0 | 0x4741e4 | 0x9dddc | 0x9cbdc | 0x9b |
LCMapStringW | 0x0 | 0x4741e8 | 0x9dde0 | 0x9cbe0 | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x4741ec | 0x9dde4 | 0x9cbe4 | 0x265 |
GetCPInfo | 0x0 | 0x4741f0 | 0x9dde8 | 0x9cbe8 | 0x1c1 |
SetEvent | 0x0 | 0x4741f4 | 0x9ddec | 0x9cbec | 0x516 |
ResetEvent | 0x0 | 0x4741f8 | 0x9ddf0 | 0x9cbf0 | 0x4c6 |
UnhandledExceptionFilter | 0x0 | 0x4741fc | 0x9ddf4 | 0x9cbf4 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x474200 | 0x9ddf8 | 0x9cbf8 | 0x56d |
IsDebuggerPresent | 0x0 | 0x474204 | 0x9ddfc | 0x9cbfc | 0x37f |
GetStartupInfoW | 0x0 | 0x474208 | 0x9de00 | 0x9cc00 | 0x2d0 |
GetCurrentProcessId | 0x0 | 0x47420c | 0x9de04 | 0x9cc04 | 0x218 |
InitializeSListHead | 0x0 | 0x474210 | 0x9de08 | 0x9cc08 | 0x363 |
LocalFree | 0x0 | 0x474214 | 0x9de0c | 0x9cc0c | 0x3cf |
CreateTimerQueue | 0x0 | 0x474218 | 0x9de10 | 0x9cc10 | 0xfa |
SignalObjectAndWait | 0x0 | 0x47421c | 0x9de14 | 0x9cc14 | 0x57b |
CreateThread | 0x0 | 0x474220 | 0x9de18 | 0x9cc18 | 0xf3 |
SetThreadPriority | 0x0 | 0x474224 | 0x9de1c | 0x9cc1c | 0x55e |
GetThreadPriority | 0x0 | 0x474228 | 0x9de20 | 0x9cc20 | 0x301 |
GetLogicalProcessorInformation | 0x0 | 0x47422c | 0x9de24 | 0x9cc24 | 0x269 |
CreateTimerQueueTimer | 0x0 | 0x474230 | 0x9de28 | 0x9cc28 | 0xfb |
ChangeTimerQueueTimer | 0x0 | 0x474234 | 0x9de2c | 0x9cc2c | 0x78 |
DeleteTimerQueueTimer | 0x0 | 0x474238 | 0x9de30 | 0x9cc30 | 0x11a |
GetNumaHighestNodeNumber | 0x0 | 0x47423c | 0x9de34 | 0x9cc34 | 0x289 |
GetProcessAffinityMask | 0x0 | 0x474240 | 0x9de38 | 0x9cc38 | 0x2af |
SetThreadAffinityMask | 0x0 | 0x474244 | 0x9de3c | 0x9cc3c | 0x553 |
RegisterWaitForSingleObject | 0x0 | 0x474248 | 0x9de40 | 0x9cc40 | 0x4a9 |
UnregisterWait | 0x0 | 0x47424c | 0x9de44 | 0x9cc44 | 0x5b6 |
GetCurrentThread | 0x0 | 0x474250 | 0x9de48 | 0x9cc48 | 0x21b |
GetThreadTimes | 0x0 | 0x474254 | 0x9de4c | 0x9cc4c | 0x305 |
FreeLibrary | 0x0 | 0x474258 | 0x9de50 | 0x9cc50 | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x47425c | 0x9de54 | 0x9cc54 | 0x1ac |
GetModuleHandleA | 0x0 | 0x474260 | 0x9de58 | 0x9cc58 | 0x275 |
LoadLibraryExW | 0x0 | 0x474264 | 0x9de5c | 0x9cc5c | 0x3c3 |
GetVersionExW | 0x0 | 0x474268 | 0x9de60 | 0x9cc60 | 0x31b |
VirtualAlloc | 0x0 | 0x47426c | 0x9de64 | 0x9cc64 | 0x5c6 |
VirtualProtect | 0x0 | 0x474270 | 0x9de68 | 0x9cc68 | 0x5cc |
VirtualFree | 0x0 | 0x474274 | 0x9de6c | 0x9cc6c | 0x5c9 |
DuplicateHandle | 0x0 | 0x474278 | 0x9de70 | 0x9cc70 | 0x12b |
ReleaseSemaphore | 0x0 | 0x47427c | 0x9de74 | 0x9cc74 | 0x4b4 |
InterlockedPopEntrySList | 0x0 | 0x474280 | 0x9de78 | 0x9cc78 | 0x36e |
InterlockedPushEntrySList | 0x0 | 0x474284 | 0x9de7c | 0x9cc7c | 0x36f |
InterlockedFlushSList | 0x0 | 0x474288 | 0x9de80 | 0x9cc80 | 0x36c |
QueryDepthSList | 0x0 | 0x47428c | 0x9de84 | 0x9cc84 | 0x443 |
UnregisterWaitEx | 0x0 | 0x474290 | 0x9de88 | 0x9cc88 | 0x5b7 |
LoadLibraryW | 0x0 | 0x474294 | 0x9de8c | 0x9cc8c | 0x3c4 |
RtlUnwind | 0x0 | 0x474298 | 0x9de90 | 0x9cc90 | 0x4d3 |
ExitProcess | 0x0 | 0x47429c | 0x9de94 | 0x9cc94 | 0x15e |
ADVAPI32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptExportKey | 0x0 | 0x474000 | 0x9dbf8 | 0x9c9f8 | 0xd0 |
RegCreateKeyW | 0x0 | 0x474004 | 0x9dbfc | 0x9c9fc | 0x267 |
RegOpenKeyExW | 0x0 | 0x474008 | 0x9dc00 | 0x9ca00 | 0x28c |
RegSetValueExW | 0x0 | 0x47400c | 0x9dc04 | 0x9ca04 | 0x2a9 |
RegCloseKey | 0x0 | 0x474010 | 0x9dc08 | 0x9ca08 | 0x25b |
CryptReleaseContext | 0x0 | 0x474014 | 0x9dc0c | 0x9ca0c | 0xdc |
CryptGenKey | 0x0 | 0x474018 | 0x9dc10 | 0x9ca10 | 0xd1 |
CryptImportKey | 0x0 | 0x47401c | 0x9dc14 | 0x9ca14 | 0xdb |
OpenProcessToken | 0x0 | 0x474020 | 0x9dc18 | 0x9ca18 | 0x215 |
GetTokenInformation | 0x0 | 0x474024 | 0x9dc1c | 0x9ca1c | 0x170 |
CloseServiceHandle | 0x0 | 0x474028 | 0x9dc20 | 0x9ca20 | 0x65 |
OpenSCManagerW | 0x0 | 0x47402c | 0x9dc24 | 0x9ca24 | 0x217 |
DeleteService | 0x0 | 0x474030 | 0x9dc28 | 0x9ca28 | 0xec |
ControlService | 0x0 | 0x474034 | 0x9dc2c | 0x9ca2c | 0x6a |
EnumDependentServicesW | 0x0 | 0x474038 | 0x9dc30 | 0x9ca30 | 0x10f |
OpenServiceW | 0x0 | 0x47403c | 0x9dc34 | 0x9ca34 | 0x219 |
QueryServiceStatusEx | 0x0 | 0x474040 | 0x9dc38 | 0x9ca38 | 0x251 |
CryptDestroyKey | 0x0 | 0x474044 | 0x9dc3c | 0x9ca3c | 0xc8 |
CryptAcquireContextW | 0x0 | 0x474048 | 0x9dc40 | 0x9ca40 | 0xc2 |
CryptEncrypt | 0x0 | 0x47404c | 0x9dc44 | 0x9ca44 | 0xcb |
CryptDuplicateKey | 0x0 | 0x474050 | 0x9dc48 | 0x9ca48 | 0xca |
RegDeleteValueW | 0x0 | 0x474054 | 0x9dc4c | 0x9ca4c | 0x273 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | 0x0 | 0x4742ec | 0x9dee4 | 0x9cce4 | 0x13a |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CLSIDFromString | 0x0 | 0x4742fc | 0x9def4 | 0x9ccf4 | 0xc |
IIDFromString | 0x0 | 0x474300 | 0x9def8 | 0x9ccf8 | 0x102 |
CoInitializeEx | 0x0 | 0x474304 | 0x9defc | 0x9ccfc | 0x5e |
CoGetObject | 0x0 | 0x474308 | 0x9df00 | 0x9cd00 | 0x51 |
CoInitialize | 0x0 | 0x47430c | 0x9df04 | 0x9cd04 | 0x5d |
CoUninitialize | 0x0 | 0x474310 | 0x9df08 | 0x9cd08 | 0x8d |
CoCreateInstance | 0x0 | 0x474314 | 0x9df0c | 0x9cd0c | 0x28 |
CoInitializeSecurity | 0x0 | 0x474318 | 0x9df10 | 0x9cd10 | 0x5f |
OLEAUT32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringByteLen | 0x96 | 0x4742b8 | 0x9deb0 | 0x9ccb0 | - |
VariantClear | 0x9 | 0x4742bc | 0x9deb4 | 0x9ccb4 | - |
SysAllocString | 0x2 | 0x4742c0 | 0x9deb8 | 0x9ccb8 | - |
SysStringByteLen | 0x95 | 0x4742c4 | 0x9debc | 0x9ccbc | - |
VariantInit | 0x8 | 0x4742c8 | 0x9dec0 | 0x9ccc0 | - |
SysFreeString | 0x6 | 0x4742cc | 0x9dec4 | 0x9ccc4 | - |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x47405c | 0x9dc54 | 0x9ca54 | 0xe3 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x4742a4 | 0x9de9c | 0x9cc9c | 0x2b |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetApiBufferFree | 0x0 | 0x4742ac | 0x9dea4 | 0x9cca4 | 0x51 |
NetShareEnum | 0x0 | 0x4742b0 | 0x9dea8 | 0x9cca8 | 0xde |
IPHLPAPI.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpSendEcho | 0x0 | 0x474064 | 0x9dc5c | 0x9ca5c | 0x99 |
IcmpCloseHandle | 0x0 | 0x474068 | 0x9dc60 | 0x9ca60 | 0x96 |
GetAdaptersInfo | 0x0 | 0x47406c | 0x9dc64 | 0x9ca64 | 0x44 |
IcmpCreateFile | 0x0 | 0x474070 | 0x9dc68 | 0x9ca68 | 0x97 |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
inet_addr | 0xb | 0x4742f4 | 0x9deec | 0x9ccec | - |
RstrtMgr.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RmShutdown | 0x0 | 0x4742d4 | 0x9decc | 0x9cccc | 0xa |
RmRegisterResources | 0x0 | 0x4742d8 | 0x9ded0 | 0x9ccd0 | 0x6 |
RmStartSession | 0x0 | 0x4742dc | 0x9ded4 | 0x9ccd4 | 0xb |
RmGetList | 0x0 | 0x4742e0 | 0x9ded8 | 0x9ccd8 | 0x4 |
RmEndSession | 0x0 | 0x4742e4 | 0x9dedc | 0x9ccdc | 0x2 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svhost.exe | 1 | 0x01250000 | 0x012FAFFF | Relevant Image |
![]() |
32-bit | 0x01289EB0 |
![]() |
![]() |
...
|
svhost.exe | 1 | 0x01250000 | 0x012FAFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\Boot\BOOTSTAT.DAT.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.networkmaze | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\READINSTRUCTION.html | Dropped File | Text |
Unknown
|
...
|
»