8d3f68b16f0710f858d8c1d2c699260e6f43161a5510abb0e7ba567bd72c965b (SHA256)
FmoAc.exe
Created at 2018-11-27 19:42:00
Notifications (2/3)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
4/5
|
File System | Modifies content of user files | Ransomware | |
|
||||
4/5
|
File System | Known malicious file | Trojan | |
|
||||
4/5
|
Injection | Writes into the memory of another running process | - | |
|
||||
|
||||
|
||||
4/5
|
Injection | Modifies control flow of another process | - | |
|
||||
|
||||
|
||||
3/5
|
Process | Creates an unusally large number of processes | - | |
|
||||
3/5
|
Persistence | Adds file to open the next time Excel is launched | - | |
|
||||
|
||||
|
||||
3/5
|
OS | Modifies certificate store | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
3/5
|
Persistence | Adds file to open the next time Word is launched | - | |
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
|
||||
|
||||
1/5
|
Process | Creates a page with write and execute permissions | - | |
|
||||
1/5
|
Anti Analysis | Resolves APIs dynamically | - | |
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
1/5
|
OS | Uses encryption API | - | |
|