9542c4da...9ff2 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Dropper, Backdoor

VMRay Threat Indicators (10 rules, 11 matches)

Severity Category Operation Classification
5/5
YARA YARA match Backdoor
  • Rule "remcos_rat" from ruleset "RATs" has matched for "".
2/5
Anti Analysis Tries to detect debugger -
2/5
Anti Analysis Resolves APIs dynamically to possibly evade static detection -
1/5
Process Creates system object -
  • Creates mutex with name "Net123432asdds-QHTWEM".
1/5
Network Performs DNS request -
1/5
Persistence Installs system startup script or application -
  • Adds "c:\users\fd1hvy\appdata\roaming\microsoft\windows\start menu\programs\startup\setx.url" to Windows startup folder.
1/5
Static Unparsable sections in file -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\FD1HVy\Desktop\laafdy.exe.
1/5
Network Connects to remote host -
  • Outgoing TCP connection to host "194.5.98.89:1530".
1/5
Network Tries to connect using an uncommon port -
  • Tries to connect to TCP port 1530 at 194.5.98.89.
1/5
PE Drops PE file Dropper

Screenshots

Monitored Processes

Sample Information

ID #1044
MD5 b6ebd9021bce7665ac01a1614ef6b7e6 Copy to Clipboard
SHA1 81109eef625dec849e60d61f8e17dc8b7d893246 Copy to Clipboard
SHA256 9542c4da58ef85804bd1240ed67bef02f5d5bca0b0084a074a3575894d929ff2 Copy to Clipboard
SSDeep 24576:KCdxte/80jYLT3U1jfsWagtD3Y37V7bLMKixQaZ:Lw80cTsjkWag+79b4KxM Copy to Clipboard
ImpHash afcdf79be1557326c854b6e20cb900a7 Copy to Clipboard
Filename laafdy.exe
File Size 1.20 MB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-04-10 13:54 (UTC+2)
Analysis Duration 00:04:41
Number of Monitored Processes 2
Execution Successful True
Reputation Enabled True
WHOIS Enabled False
Local AV Enabled False
YARA Enabled True
Number of YARA Matches 18
Termination Reason Timeout
Tags
#malware
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image