65b988f2...1008 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification:
Ransomware
Downloader
Threat Names:
Djvu
STOP
Trojan.GenericKD.31534187
...

Remarks (2/3)

(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 minute, 45 seconds" to "10 seconds" to reveal dormant functionality.

(0x02000004): The operating system was rebooted during the analysis because the sample installed a startup script, task or application for persistence.

(0x0200003A): 2 tasks were rescheduled ahead of time to reveal dormant functionality.

VMRay Threat Identifiers (20 rules, 147 matches)

SeverityCategoryOperationCountClassification
5/5
AntivirusMalicious content was detected by heuristic scan7-
5/5
ReputationKnown malicious file3-
5/5
YARAMalicious content matched by YARA rules101Ransomware
4/5
User Data ModificationModifies content of user files1Ransomware
4/5
User Data ModificationRenames user files1Ransomware
4/5
ReputationContacts known malicious URL7-
3/5
YARASuspicious content matched by YARA rules6-
2/5
ObfuscationResolves APIs dynamically to possibly evade static detection1-
2/5
Hide TracksDeletes file after execution1-
2/5
Task SchedulingSchedules task1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Scheduled Task
Persistence
Scheduled Task
Registry Run Keys / Startup Folder
Privilege Escalation
Scheduled Task
Defense Evasion
Software Packing
Hidden Window
Modify Registry
Credential Access
Discovery
System Network Connections Discovery
System Network Configuration Discovery
Process Discovery
Lateral Movement
Remote File Copy
Collection
Command and Control
Remote File Copy
Standard Application Layer Protocol
Standard Cryptographic Protocol
Exfiltration
Impact
Data Encrypted for Impact

Sample Information

ID#1408453
MD5
7cfc5575759906a2de75c972578d9204
SHA1
b911a17da3c8ce87fdc3bc1c2caca9d3439b7202
SHA256
65b988f2abe4047f8940e2e98131e8d9b7eda217afca673ed99fd9adb6ab1008
SSDeep
12288:dbaYe1PviidEDUoq1O27Y4tiaiTZztkwdlQs9FZYRGCcKvYm2B5McpK:dOPvufq1O8vCTSG9KA
ImpHash
aa1da305e55a1f541884d9f2ef7e57c7
FilenameOnB5h0yX46mreVq4.exe
File Size687.00 KB
Sample TypeWindows Exe (x86-32)

Analysis Information

Creation Time2020-10-05 05:10 (UTC+)
Analysis Duration00:04:00
Number of Monitored Processes11
Execution SuccessfulTrue
Reputation EnabledTrue
WHOIS EnabledFalse
Local AV EnabledTrue
Local AV Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
YARA EnabledTrue
YARA Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
Number of AV Matches26
Number of YARA Matches129
Termination ReasonTimeout
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image