7106abd9...dedb | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification:
Ransomware
Threat Names:
Gen:Heur.Ransom.HiddenTears.1

VMRay Threat Identifiers (5 rules, 5 matches)

SeverityCategoryOperationCountClassification
5/5
AntivirusMalicious content was detected by heuristic scan1-
4/5
User Data ModificationModifies content of user files1Ransomware
4/5
User Data ModificationRenames user files1Ransomware
2/5
Hide TracksHides files1-
1/5
System ModificationCreates an unusually large number of files1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Persistence
Hidden Files and Directories
Privilege Escalation
Defense Evasion
Hidden Files and Directories
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Data Encrypted for Impact

Sample Information

ID#450070
MD5
5b592199a0fa0eea00e9a7c39efb4cdc
SHA1
da1d3b56bf5443da05b53928190ae73493596209
SHA256
7106abd949facec5c437f730d05b2c69a2aa1e2bde1bf8d6c4789f5e0ba5dedb
SSDeep
3072:gaM+lmsolAIrRuw+mqv9j1MWLQXMTmmsolNIrRuw+mqv9j1MWLQbFto:Y+lDAAFTmDANut
ImpHash
f34d5f2d4577ed6d9ceec516c1f5a744
FilenameDRV.exe
File Size211.00 kB
Sample TypeWindows Exe (x86-32)

Analysis Information

Creation Time2020-02-02 05:02 (UTC+)
Analysis Duration00:04:00
Number of Monitored Processes2
Execution SuccessfulTrue
Reputation EnabledTrue
WHOIS EnabledFalse
Local AV EnabledTrue
Local AV Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
YARA EnabledTrue
YARA Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
Number of AV Matches1
Number of YARA Matches0
Termination ReasonTimeout
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image