VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan, Worm |
l25de3a0fbaa3009886613f5e62b92f2.exe
Windows Exe (x86-32)
Created at 2019-09-28T15:52:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\l25de3a0fbaa3009886613f5e62b92f2.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-09 14:51 (UTC+2) |
Last Seen | 2019-09-27 03:22 (UTC+2) |
Names | ByteCode-MSIL.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4161de |
Size Of Code | 0x15000 |
Size Of Initialized Data | 0x2000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-09 09:21:48+00:00 |
Version Information (8)
»
Assembly Version | 1.0.7129.18654 |
FileDescription | l25de3a0fbaa3009886613f5e62b92f2 |
FileVersion | 1.0.7129.18654 |
InternalName | l25de3a0fbaa3009886613f5e62b92f2.exe |
LegalCopyright | Copyright 2019 |
OriginalFilename | l25de3a0fbaa3009886613f5e62b92f2.exe |
ProductName | l25de3a0fbaa3009886613f5e62b92f2 |
ProductVersion | 1.0.7129.18654 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x141e4 | 0x15000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.5 |
.rsrc | 0x418000 | 0x800 | 0x1000 | 0x16000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.8 |
.reloc | 0x41a000 | 0xc | 0x1000 | 0x17000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x161ac | 0x151ac | 0x0 |
Memory Dumps (26)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00BBB000 | 0x00BBBFFF | First Execution | - | 32-bit | 0x00BBB000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00BE6000 | 0x00BE6FFF | First Execution | - | 32-bit | 0x00BE6012 |
![]() |
![]() |
...
|
buffer | 1 | 0x066B1000 | 0x066B1FFF | First Execution | - | 32-bit | 0x066B1000 |
![]() |
![]() |
...
|
buffer | 1 | 0x04B71000 | 0x04B71FFF | First Execution | - | 32-bit | 0x04B71000 |
![]() |
![]() |
...
|
buffer | 1 | 0x025C1000 | 0x025C1FFF | First Execution | - | 32-bit | 0x025C103C |
![]() |
![]() |
...
|
buffer | 1 | 0x00BE6000 | 0x00BE6FFF | Content Changed | - | 32-bit | 0x00BE6032 |
![]() |
![]() |
...
|
buffer | 1 | 0x00BBB000 | 0x00BBBFFF | Content Changed | - | 32-bit | 0x00BBB000 |
![]() |
![]() |
...
|
buffer | 1 | 0x066B2000 | 0x066B2FFF | First Execution | - | 32-bit | 0x066B200C |
![]() |
![]() |
...
|
buffer | 1 | 0x066B1000 | 0x066B1FFF | Content Changed | - | 32-bit | 0x066B1243 |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | First Execution | - | 32-bit | 0x025C41DA |
![]() |
![]() |
...
|
buffer | 1 | 0x04B71000 | 0x04B71FFF | Content Changed | - | 32-bit | 0x04B715C7 |
![]() |
![]() |
...
|
buffer | 1 | 0x066B2000 | 0x066B2FFF | Content Changed | - | 32-bit | 0x066B200C |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C44AA |
![]() |
![]() |
...
|
buffer | 1 | 0x025C1000 | 0x025C1FFF | Content Changed | - | 32-bit | 0x025C103C |
![]() |
![]() |
...
|
buffer | 1 | 0x00BBB000 | 0x00BBBFFF | Content Changed | - | 32-bit | 0x00BBB054 |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C435A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C429A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C1000 | 0x025C1FFF | Content Changed | - | 32-bit | 0x025C103C |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C44DA |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C447A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C435A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C4C8A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C1000 | 0x025C1FFF | Content Changed | - | 32-bit | 0x025C103C |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C4ADA |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C4E9A |
![]() |
![]() |
...
|
buffer | 1 | 0x025C4000 | 0x025C5FFF | Content Changed | - | 32-bit | 0x025C50AA |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
OlympicDestroyer_Gen1 | Olympic Destroyer destructive malware | Worm |
5/5
|
...
|
C:\Users\desktop.ini.XurKlX#wg4XM44IZQpq48g==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.0.xml.kl3sfeyr4zr2hytlakd56g==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.1.xml.axvyvu1kxlk9hzb1jjfrlw==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.2.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\0d0d4eeb-dc03-4b3f-88df-959fe1ede5f4\en-us.16\masterdescriptor.en-us.xml.+du80ckozbrso8w6mqef6a==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\0d0d4eeb-dc03-4b3f-88df-959fe1ede5f4\x-none.16\masterdescriptor.x-none.xml.npeerzw2uhon1xmfzmkc1q==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\19b11135-37bd-4fa1-a78e-c20ca2bda1c0\en-us.16\masterdescriptor.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\19b11135-37bd-4fa1-a78e-c20ca2bda1c0\x-none.16\masterdescriptor.x-none.xml.dn#nzpairwzqre2j2ssx8g==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\201eb7df-c721-4b8b-9c81-a09de7f931e6\en-us.16\masterdescriptor.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\201eb7df-c721-4b8b-9c81-a09de7f931e6\x-none.16\masterdescriptor.x-none.xml.zy109leglcjedtp+ozgtca==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\deploymentconfiguration.xml.vhsw9krh9ks1crqf8rpo9w==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\manifest.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\userdeploymentconfiguration.xml | Modified File | Binary |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\machinedata\catalog\packages\{9ac08e99-230b-47e8-9721-4577b7f124ea}\{1a8308c7-90d1-4200-b16e-646f163a08e8}\usermanifest.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\en-us.16\masterdescriptor.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\en-us.16\stream.platform.culture.man.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\x-none.16\masterdescriptor.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\productreleases\5a65c4d7-3cdf-4be4-8560-f036d300c13f\x-none.16\stream.platform.x-none.man.xml.md3j23joihah#mmhwp+78q==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.access.access.x-none.msi.16.x-none.xml.so8000ixlyhilxg7gdbdvw==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.accessmuiset.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcf.dcf.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.dcfmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excel.excel.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.excelmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groove.groove.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.groovemui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lync.lync.x-none.msi.16.x-none.xml.r1d9h1tx#xfizlncdh0cnq==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.lyncmui.msi.16.en-us.xml.#mea#7rdbvdzaxhpgvoegw==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office32mui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.office32ww.msi.16.x-none.xml.vvk4am33q21#lgjsybi9ka==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemui.msi.16.en-us.xml.m1igyqzjygyq4dob#bitvg==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.officemuiset.msi.16.en-us.xml.09kiw8wqhljwyj55fugylg==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenote.onenote.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.onenotemui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osm.osm.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmux.osmux.x-none.msi.16.x-none.xml.j+mncajsj38mcekf6sit2q==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.osmuxmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlook.outlook.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.outlookmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpivot.powerpivot.x-none.msi.16.x-none.xml.hrfpkhdqc+zxstaomdz9tg==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpoint.powerpoint.x-none.msi.16.x-none.xml.8swr6urc9lteee0oiujgtq==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.powerpointmui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.project.project.x-none.msi.16.x-none.xml.8u3rucsg5nzqzfyhs+ayxg==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.projectmui.msi.16.en-us.xml.wkiyawai1tfv+jeauspvbq==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.en-us.xml.fp+nk3vsmfkkivzsvcw58w==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.es-es.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proof.culture.msi.16.fr-fr.xml.uojxtgeje#9#o22fd2dh0g==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.proofing.msi.16.en-us.xml.4tip0dxjzuu98uqf#utlgq==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publisher.publisher.x-none.msi.16.x-none.xml.8smzrdjzp5vbxsnxuotflq==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.publishermui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.shared.office.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.visio.visio.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.visiomui.msi.16.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.word.word.x-none.msi.16.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\c2rmanifest.wordmui.msi.16.en-us.xml.ykfbc#wyb2jtyde#ix4gfa==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentfallback2016.xml.h5qnpv28ukjg4u4frubt0a==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\microsoft_office_officetelemetryagentlogon2016.xml.m9e7mpnw68gggi7hrnzsoa==.bwall | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\readme-bw-gffl.txt | Dropped File | Text |
Unknown
|
...
|
»