VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
noitidetsrif.exe
Windows Exe (x86-32)
Created at 2019-06-24T22:39:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\noitidetsrif.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-06-21 19:43 (UTC+2) |
Last Seen | 2019-06-24 20:49 (UTC+2) |
Names | ByteCode-MSIL.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406566 |
Size Of Code | 0x4600 |
Size Of Initialized Data | 0xe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2084-11-12 04:03:10+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | noitidetsrif |
FileVersion | 1.0.0.0 |
InternalName | noitidetsrif.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | noitidetsrif.exe |
ProductName | noitidetsrif |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x456c | 0x4600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.11 |
.rsrc | 0x408000 | 0xac0 | 0xc00 | 0x4800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.34 |
.reloc | 0x40a000 | 0xc | 0x200 | 0x5400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x653b | 0x473b | 0x0 |
Memory Dumps (28)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B1910, 0x747B24A8, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B1918 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CA604 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C35F0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B326C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C922C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C0007 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747BC88C, 0x7487C78C, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C705C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747BEAE0, 0x747C4000 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x74878B90, 0x747CB06C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C8D4C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x74893294, 0x74892AAC |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CC000 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C6410 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C56B0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C1364, 0x74879480, ... |
![]() |
![]() |
...
|
buffer | 1 | 0x04BF1000 | 0x04BF1FFF | First Execution | - | 32-bit | 0x04BF1206 |
![]() |
![]() |
...
|
buffer | 1 | 0x00242000 | 0x00242FFF | First Execution | - | 32-bit | 0x00242EE0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C1690, 0x747BF920, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B1988, 0x747BE858 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B32AC, 0x747C922C, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C23D0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C5970, 0x747C4090 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CC528 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CAEBC, 0x747C3FD0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C6820, 0x747C8F10 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C68D8, 0x747C7954, ... |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.41387691 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\0fXSoYyeJ82KkswLWm.wav.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\desktop.ini.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\KKTSZ.mp3.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Q4MZzE8.wav.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\desktop.ini.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\HNRbZQ6.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\JKFekB4feQgcHwoHVFB.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\m RI.png.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\R24NZ1BjqYMgeIvExG.png.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\tfqJGoHzfZ6i.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Y0q0rRmTvvdvBeH.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Z_ULXMFau.bmp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-XPt8YTaiAPsxF1LOj.xls.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0bJX1ZmT_7FZfn.csv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\16_6KBuq38ydo7.jpg.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2FtUP.wav.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3tpXV7e6d.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5UjqRR-Ub7uIuY.odp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9QYo.mkv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Bk0yhoNpUIak.mkv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Bo_r4COe151g.m4a.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cAuM4I.flv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\desktop.ini.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dy79t7HL.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ESjnDz-.jpg.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f6VlxrksN5AyYmhyHE7.bmp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FWYtecM5teqj.m4a.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jIvWV3m8ltx3Efp.mkv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JXoiFmBBllm.ods.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LbY7.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NkDEd0.bmp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NluNY2i.mp3.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\oe_UDjK5dglAj.png.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OPEX rQi2p5pE.swf.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\P9e_n.bmp.litra | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PwKLg1 z.mp3.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rrPLmEe.bmp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SxQNG.mkv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\viLm.bmp.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xh-IzNeDJf56yg43d-.png.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YySUDMilQuO.mp3.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZjDcKJFJVpuw1VY.m4a.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZVx77Uk6cs.mp4.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-5ovc5Zjg-V24VlVviIY.docx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0JFN cDosf1O BBErFFe.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\42T9W87rqI_.csv.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4sUXj1UPF-.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\65q3O.ppt.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7srwU3T1rT02OYtKGq.ots.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9ot5SO.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\C5g048Y8S2.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CZccI.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\desktop.ini.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\iJWNI.docx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\j2xvAHsoCbW_lcjYe0iF.docx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J79kQ0LAFP2jV.docx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Jdc1FwyylM_V.ots.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lQ412CZdlCABKG.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LQIXpj.odt.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OANAwe.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OEO5j_ynKCNGOzrxY.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Sk2r-nEmibcrb e.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tzTg9gqfq-oiz QbbNO.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\UJc7MXkH_2.doc.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VAXRo.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Vh4gGtXSmEm6XoEv.xls.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wgnNK 4geXIg25gQA.docx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_6gJ.xlsx.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\mn9UghYWgPQe.avi.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\toujiXE7X_F_AmdJOdD.avi.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\tQUA10MJgPpbvdTdKW4.swf.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rh3XTu3.gif.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\U2w5SGIB3Z78iuNMBa6Y.xls.litra | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xUit7Mu_Jjy0hUZ1.pptx.litra | Dropped File | Stream |
Unknown
|
...
|
»