VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Variant.Razy.614482
Mal/Generic-S
|
jyotrn.exe
Windows Exe (x86-32)
Created at 2020-03-11T12:42:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jyotrn.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401363 |
Size Of Code | 0xe800 |
Size Of Initialized Data | 0x6a800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-19 14:01:27+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xe6df | 0xe800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.6 |
.rdata | 0x410000 | 0x5ebc | 0x6000 | 0xec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.82 |
.data | 0x416000 | 0x634f0 | 0x62c00 | 0x14c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.59 |
.rsrc | 0x47a000 | 0x1e0 | 0x200 | 0x77800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x47b000 | 0xf30 | 0x1000 | 0x77a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.42 |
Imports (3)
»
KERNEL32.dll (73)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateToolhelp32Snapshot | 0x0 | 0x410000 | 0x157fc | 0x143fc | 0xfc |
Process32NextW | 0x0 | 0x410004 | 0x15800 | 0x14400 | 0x42e |
Process32FirstW | 0x0 | 0x410008 | 0x15804 | 0x14404 | 0x42c |
CloseHandle | 0x0 | 0x41000c | 0x15808 | 0x14408 | 0x86 |
GetConsoleWindow | 0x0 | 0x410010 | 0x1580c | 0x1440c | 0x207 |
WriteConsoleW | 0x0 | 0x410014 | 0x15810 | 0x14410 | 0x611 |
SetEndOfFile | 0x0 | 0x410018 | 0x15814 | 0x14414 | 0x510 |
HeapReAlloc | 0x0 | 0x41001c | 0x15818 | 0x14418 | 0x34c |
HeapSize | 0x0 | 0x410020 | 0x1581c | 0x1441c | 0x34e |
ReadConsoleW | 0x0 | 0x410024 | 0x15820 | 0x14420 | 0x470 |
UnhandledExceptionFilter | 0x0 | 0x410028 | 0x15824 | 0x14424 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x41002c | 0x15828 | 0x14428 | 0x56d |
GetCurrentProcess | 0x0 | 0x410030 | 0x1582c | 0x1442c | 0x217 |
TerminateProcess | 0x0 | 0x410034 | 0x15830 | 0x14430 | 0x58c |
IsProcessorFeaturePresent | 0x0 | 0x410038 | 0x15834 | 0x14434 | 0x386 |
QueryPerformanceCounter | 0x0 | 0x41003c | 0x15838 | 0x14438 | 0x44d |
GetCurrentProcessId | 0x0 | 0x410040 | 0x1583c | 0x1443c | 0x218 |
GetCurrentThreadId | 0x0 | 0x410044 | 0x15840 | 0x14440 | 0x21c |
GetSystemTimeAsFileTime | 0x0 | 0x410048 | 0x15844 | 0x14444 | 0x2e9 |
InitializeSListHead | 0x0 | 0x41004c | 0x15848 | 0x14448 | 0x363 |
IsDebuggerPresent | 0x0 | 0x410050 | 0x1584c | 0x1444c | 0x37f |
GetStartupInfoW | 0x0 | 0x410054 | 0x15850 | 0x14450 | 0x2d0 |
GetModuleHandleW | 0x0 | 0x410058 | 0x15854 | 0x14454 | 0x278 |
RtlUnwind | 0x0 | 0x41005c | 0x15858 | 0x14458 | 0x4d3 |
GetLastError | 0x0 | 0x410060 | 0x1585c | 0x1445c | 0x261 |
SetLastError | 0x0 | 0x410064 | 0x15860 | 0x14460 | 0x532 |
EnterCriticalSection | 0x0 | 0x410068 | 0x15864 | 0x14464 | 0x131 |
LeaveCriticalSection | 0x0 | 0x41006c | 0x15868 | 0x14468 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x410070 | 0x1586c | 0x1446c | 0x110 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x410074 | 0x15870 | 0x14470 | 0x35f |
TlsAlloc | 0x0 | 0x410078 | 0x15874 | 0x14474 | 0x59e |
TlsGetValue | 0x0 | 0x41007c | 0x15878 | 0x14478 | 0x5a0 |
TlsSetValue | 0x0 | 0x410080 | 0x1587c | 0x1447c | 0x5a1 |
TlsFree | 0x0 | 0x410084 | 0x15880 | 0x14480 | 0x59f |
FreeLibrary | 0x0 | 0x410088 | 0x15884 | 0x14484 | 0x1ab |
GetProcAddress | 0x0 | 0x41008c | 0x15888 | 0x14488 | 0x2ae |
LoadLibraryExW | 0x0 | 0x410090 | 0x1588c | 0x1448c | 0x3c3 |
RaiseException | 0x0 | 0x410094 | 0x15890 | 0x14490 | 0x462 |
GetStdHandle | 0x0 | 0x410098 | 0x15894 | 0x14494 | 0x2d2 |
WriteFile | 0x0 | 0x41009c | 0x15898 | 0x14498 | 0x612 |
GetModuleFileNameW | 0x0 | 0x4100a0 | 0x1589c | 0x1449c | 0x274 |
ExitProcess | 0x0 | 0x4100a4 | 0x158a0 | 0x144a0 | 0x15e |
GetModuleHandleExW | 0x0 | 0x4100a8 | 0x158a4 | 0x144a4 | 0x277 |
GetCommandLineA | 0x0 | 0x4100ac | 0x158a8 | 0x144a8 | 0x1d6 |
GetCommandLineW | 0x0 | 0x4100b0 | 0x158ac | 0x144ac | 0x1d7 |
HeapFree | 0x0 | 0x4100b4 | 0x158b0 | 0x144b0 | 0x349 |
GetConsoleCP | 0x0 | 0x4100b8 | 0x158b4 | 0x144b4 | 0x1ea |
GetConsoleMode | 0x0 | 0x4100bc | 0x158b8 | 0x144b8 | 0x1fc |
GetFileSizeEx | 0x0 | 0x4100c0 | 0x158bc | 0x144bc | 0x24c |
SetFilePointerEx | 0x0 | 0x4100c4 | 0x158c0 | 0x144c0 | 0x523 |
HeapAlloc | 0x0 | 0x4100c8 | 0x158c4 | 0x144c4 | 0x345 |
FindClose | 0x0 | 0x4100cc | 0x158c8 | 0x144c8 | 0x175 |
FindFirstFileExW | 0x0 | 0x4100d0 | 0x158cc | 0x144cc | 0x17b |
FindNextFileW | 0x0 | 0x4100d4 | 0x158d0 | 0x144d0 | 0x18c |
IsValidCodePage | 0x0 | 0x4100d8 | 0x158d4 | 0x144d4 | 0x38b |
GetACP | 0x0 | 0x4100dc | 0x158d8 | 0x144d8 | 0x1b2 |
GetOEMCP | 0x0 | 0x4100e0 | 0x158dc | 0x144dc | 0x297 |
GetCPInfo | 0x0 | 0x4100e4 | 0x158e0 | 0x144e0 | 0x1c1 |
MultiByteToWideChar | 0x0 | 0x4100e8 | 0x158e4 | 0x144e4 | 0x3ef |
WideCharToMultiByte | 0x0 | 0x4100ec | 0x158e8 | 0x144e8 | 0x5fe |
GetEnvironmentStringsW | 0x0 | 0x4100f0 | 0x158ec | 0x144ec | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x4100f4 | 0x158f0 | 0x144f0 | 0x1aa |
SetEnvironmentVariableW | 0x0 | 0x4100f8 | 0x158f4 | 0x144f4 | 0x514 |
SetStdHandle | 0x0 | 0x4100fc | 0x158f8 | 0x144f8 | 0x54a |
GetFileType | 0x0 | 0x410100 | 0x158fc | 0x144fc | 0x24e |
GetStringTypeW | 0x0 | 0x410104 | 0x15900 | 0x14500 | 0x2d7 |
CompareStringW | 0x0 | 0x410108 | 0x15904 | 0x14504 | 0x9b |
LCMapStringW | 0x0 | 0x41010c | 0x15908 | 0x14508 | 0x3b1 |
GetProcessHeap | 0x0 | 0x410110 | 0x1590c | 0x1450c | 0x2b4 |
CreateFileW | 0x0 | 0x410114 | 0x15910 | 0x14510 | 0xcb |
FlushFileBuffers | 0x0 | 0x410118 | 0x15914 | 0x14514 | 0x19f |
ReadFile | 0x0 | 0x41011c | 0x15918 | 0x14518 | 0x473 |
DecodePointer | 0x0 | 0x410120 | 0x1591c | 0x1451c | 0x109 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x410130 | 0x1592c | 0x1452c | 0x380 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x410128 | 0x15924 | 0x14524 | 0x1b7 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
jyotrn.exe | 1 | 0x00A00000 | 0x00A7BFFF | Relevant Image |
![]() |
32-bit | 0x00A0EDA3 |
![]() |
![]() |
...
|
jyotrn.exe | 1 | 0x00A00000 | 0x00A7BFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:/Users/Public/Documents/wincproc.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x42201a |
Size Of Code | 0x47e00 |
Size Of Initialized Data | 0x1b200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-18 21:22:52+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x47c78 | 0x47e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x449000 | 0x144a4 | 0x14600 | 0x48200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.38 |
.data | 0x45e000 | 0x2db4 | 0x1c00 | 0x5c800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
.reloc | 0x461000 | 0x3c90 | 0x3e00 | 0x5e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.54 |
Imports (4)
»
KERNEL32.dll (103)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLogicalDriveStringsW | 0x0 | 0x44901c | 0x5ca50 | 0x5bc50 | 0x267 |
CreateToolhelp32Snapshot | 0x0 | 0x449020 | 0x5ca54 | 0x5bc54 | 0xfc |
Process32NextW | 0x0 | 0x449024 | 0x5ca58 | 0x5bc58 | 0x42e |
GetDiskFreeSpaceExW | 0x0 | 0x449028 | 0x5ca5c | 0x5bc5c | 0x228 |
Process32FirstW | 0x0 | 0x44902c | 0x5ca60 | 0x5bc60 | 0x42c |
CloseHandle | 0x0 | 0x449030 | 0x5ca64 | 0x5bc64 | 0x86 |
OpenProcess | 0x0 | 0x449034 | 0x5ca68 | 0x5bc68 | 0x40d |
lstrcpyW | 0x0 | 0x449038 | 0x5ca6c | 0x5bc6c | 0x636 |
lstrcmpW | 0x0 | 0x44903c | 0x5ca70 | 0x5bc70 | 0x630 |
GetDriveTypeW | 0x0 | 0x449040 | 0x5ca74 | 0x5bc74 | 0x22f |
SetEndOfFile | 0x0 | 0x449044 | 0x5ca78 | 0x5bc78 | 0x510 |
WriteConsoleW | 0x0 | 0x449048 | 0x5ca7c | 0x5bc7c | 0x611 |
HeapSize | 0x0 | 0x44904c | 0x5ca80 | 0x5bc80 | 0x34e |
FindClose | 0x0 | 0x449050 | 0x5ca84 | 0x5bc84 | 0x175 |
GetModuleFileNameW | 0x0 | 0x449054 | 0x5ca88 | 0x5bc88 | 0x274 |
TerminateProcess | 0x0 | 0x449058 | 0x5ca8c | 0x5bc8c | 0x58c |
lstrlenW | 0x0 | 0x44905c | 0x5ca90 | 0x5bc90 | 0x63c |
FindNextFileW | 0x0 | 0x449060 | 0x5ca94 | 0x5bc94 | 0x18c |
GetConsoleWindow | 0x0 | 0x449064 | 0x5ca98 | 0x5bc98 | 0x207 |
FindFirstFileW | 0x0 | 0x449068 | 0x5ca9c | 0x5bc9c | 0x180 |
CreateFileW | 0x0 | 0x44906c | 0x5caa0 | 0x5bca0 | 0xcb |
SetStdHandle | 0x0 | 0x449070 | 0x5caa4 | 0x5bca4 | 0x54a |
GetProcessHeap | 0x0 | 0x449074 | 0x5caa8 | 0x5bca8 | 0x2b4 |
SetEnvironmentVariableW | 0x0 | 0x449078 | 0x5caac | 0x5bcac | 0x514 |
FreeEnvironmentStringsW | 0x0 | 0x44907c | 0x5cab0 | 0x5bcb0 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x449080 | 0x5cab4 | 0x5bcb4 | 0x237 |
GetOEMCP | 0x0 | 0x449084 | 0x5cab8 | 0x5bcb8 | 0x297 |
MultiByteToWideChar | 0x0 | 0x449088 | 0x5cabc | 0x5bcbc | 0x3ef |
GetLastError | 0x0 | 0x44908c | 0x5cac0 | 0x5bcc0 | 0x261 |
WideCharToMultiByte | 0x0 | 0x449090 | 0x5cac4 | 0x5bcc4 | 0x5fe |
GetStringTypeW | 0x0 | 0x449094 | 0x5cac8 | 0x5bcc8 | 0x2d7 |
GetCurrentThreadId | 0x0 | 0x449098 | 0x5cacc | 0x5bccc | 0x21c |
WaitForSingleObjectEx | 0x0 | 0x44909c | 0x5cad0 | 0x5bcd0 | 0x5d8 |
SwitchToThread | 0x0 | 0x4490a0 | 0x5cad4 | 0x5bcd4 | 0x587 |
GetExitCodeThread | 0x0 | 0x4490a4 | 0x5cad8 | 0x5bcd8 | 0x23d |
EnterCriticalSection | 0x0 | 0x4490a8 | 0x5cadc | 0x5bcdc | 0x131 |
LeaveCriticalSection | 0x0 | 0x4490ac | 0x5cae0 | 0x5bce0 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x4490b0 | 0x5cae4 | 0x5bce4 | 0x110 |
SetLastError | 0x0 | 0x4490b4 | 0x5cae8 | 0x5bce8 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4490b8 | 0x5caec | 0x5bcec | 0x35f |
TlsAlloc | 0x0 | 0x4490bc | 0x5caf0 | 0x5bcf0 | 0x59e |
TlsGetValue | 0x0 | 0x4490c0 | 0x5caf4 | 0x5bcf4 | 0x5a0 |
TlsSetValue | 0x0 | 0x4490c4 | 0x5caf8 | 0x5bcf8 | 0x5a1 |
TlsFree | 0x0 | 0x4490c8 | 0x5cafc | 0x5bcfc | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x4490cc | 0x5cb00 | 0x5bd00 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x4490d0 | 0x5cb04 | 0x5bd04 | 0x278 |
GetProcAddress | 0x0 | 0x4490d4 | 0x5cb08 | 0x5bd08 | 0x2ae |
EncodePointer | 0x0 | 0x4490d8 | 0x5cb0c | 0x5bd0c | 0x12d |
DecodePointer | 0x0 | 0x4490dc | 0x5cb10 | 0x5bd10 | 0x109 |
QueryPerformanceCounter | 0x0 | 0x4490e0 | 0x5cb14 | 0x5bd14 | 0x44d |
CompareStringW | 0x0 | 0x4490e4 | 0x5cb18 | 0x5bd18 | 0x9b |
LCMapStringW | 0x0 | 0x4490e8 | 0x5cb1c | 0x5bd1c | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x4490ec | 0x5cb20 | 0x5bd20 | 0x265 |
GetCPInfo | 0x0 | 0x4490f0 | 0x5cb24 | 0x5bd24 | 0x1c1 |
UnhandledExceptionFilter | 0x0 | 0x4490f4 | 0x5cb28 | 0x5bd28 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x4490f8 | 0x5cb2c | 0x5bd2c | 0x56d |
GetCurrentProcess | 0x0 | 0x4490fc | 0x5cb30 | 0x5bd30 | 0x217 |
IsProcessorFeaturePresent | 0x0 | 0x449100 | 0x5cb34 | 0x5bd34 | 0x386 |
IsDebuggerPresent | 0x0 | 0x449104 | 0x5cb38 | 0x5bd38 | 0x37f |
GetStartupInfoW | 0x0 | 0x449108 | 0x5cb3c | 0x5bd3c | 0x2d0 |
GetCurrentProcessId | 0x0 | 0x44910c | 0x5cb40 | 0x5bd40 | 0x218 |
InitializeSListHead | 0x0 | 0x449110 | 0x5cb44 | 0x5bd44 | 0x363 |
SetEvent | 0x0 | 0x449114 | 0x5cb48 | 0x5bd48 | 0x516 |
CreateThread | 0x0 | 0x449118 | 0x5cb4c | 0x5bd4c | 0xf3 |
GetCurrentThread | 0x0 | 0x44911c | 0x5cb50 | 0x5bd50 | 0x21b |
GetThreadTimes | 0x0 | 0x449120 | 0x5cb54 | 0x5bd54 | 0x305 |
FreeLibrary | 0x0 | 0x449124 | 0x5cb58 | 0x5bd58 | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x449128 | 0x5cb5c | 0x5bd5c | 0x1ac |
LoadLibraryExW | 0x0 | 0x44912c | 0x5cb60 | 0x5bd60 | 0x3c3 |
WaitForSingleObject | 0x0 | 0x449130 | 0x5cb64 | 0x5bd64 | 0x5d7 |
RtlUnwind | 0x0 | 0x449134 | 0x5cb68 | 0x5bd68 | 0x4d3 |
RaiseException | 0x0 | 0x449138 | 0x5cb6c | 0x5bd6c | 0x462 |
ExitThread | 0x0 | 0x44913c | 0x5cb70 | 0x5bd70 | 0x15f |
GetModuleHandleExW | 0x0 | 0x449140 | 0x5cb74 | 0x5bd74 | 0x277 |
ExitProcess | 0x0 | 0x449144 | 0x5cb78 | 0x5bd78 | 0x15e |
GetStdHandle | 0x0 | 0x449148 | 0x5cb7c | 0x5bd7c | 0x2d2 |
WriteFile | 0x0 | 0x44914c | 0x5cb80 | 0x5bd80 | 0x612 |
GetCommandLineA | 0x0 | 0x449150 | 0x5cb84 | 0x5bd84 | 0x1d6 |
GetCommandLineW | 0x0 | 0x449154 | 0x5cb88 | 0x5bd88 | 0x1d7 |
HeapAlloc | 0x0 | 0x449158 | 0x5cb8c | 0x5bd8c | 0x345 |
HeapFree | 0x0 | 0x44915c | 0x5cb90 | 0x5bd90 | 0x349 |
GetDateFormatW | 0x0 | 0x449160 | 0x5cb94 | 0x5bd94 | 0x221 |
GetTimeFormatW | 0x0 | 0x449164 | 0x5cb98 | 0x5bd98 | 0x30c |
IsValidLocale | 0x0 | 0x449168 | 0x5cb9c | 0x5bd9c | 0x38d |
GetUserDefaultLCID | 0x0 | 0x44916c | 0x5cba0 | 0x5bda0 | 0x312 |
EnumSystemLocalesW | 0x0 | 0x449170 | 0x5cba4 | 0x5bda4 | 0x154 |
GetFileSizeEx | 0x0 | 0x449174 | 0x5cba8 | 0x5bda8 | 0x24c |
SetFilePointerEx | 0x0 | 0x449178 | 0x5cbac | 0x5bdac | 0x523 |
GetFileType | 0x0 | 0x44917c | 0x5cbb0 | 0x5bdb0 | 0x24e |
FlushFileBuffers | 0x0 | 0x449180 | 0x5cbb4 | 0x5bdb4 | 0x19f |
GetConsoleCP | 0x0 | 0x449184 | 0x5cbb8 | 0x5bdb8 | 0x1ea |
GetConsoleMode | 0x0 | 0x449188 | 0x5cbbc | 0x5bdbc | 0x1fc |
GetExitCodeProcess | 0x0 | 0x44918c | 0x5cbc0 | 0x5bdc0 | 0x23c |
CreateProcessW | 0x0 | 0x449190 | 0x5cbc4 | 0x5bdc4 | 0xe5 |
GetFileAttributesExW | 0x0 | 0x449194 | 0x5cbc8 | 0x5bdc8 | 0x242 |
MoveFileExW | 0x0 | 0x449198 | 0x5cbcc | 0x5bdcc | 0x3e8 |
ReadFile | 0x0 | 0x44919c | 0x5cbd0 | 0x5bdd0 | 0x473 |
ReadConsoleW | 0x0 | 0x4491a0 | 0x5cbd4 | 0x5bdd4 | 0x470 |
HeapReAlloc | 0x0 | 0x4491a4 | 0x5cbd8 | 0x5bdd8 | 0x34c |
GetTimeZoneInformation | 0x0 | 0x4491a8 | 0x5cbdc | 0x5bddc | 0x30e |
FindFirstFileExW | 0x0 | 0x4491ac | 0x5cbe0 | 0x5bde0 | 0x17b |
IsValidCodePage | 0x0 | 0x4491b0 | 0x5cbe4 | 0x5bde4 | 0x38b |
GetACP | 0x0 | 0x4491b4 | 0x5cbe8 | 0x5bde8 | 0x1b2 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x4491bc | 0x5cbf0 | 0x5bdf0 | 0x380 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExW | 0x0 | 0x449000 | 0x5ca34 | 0x5bc34 | 0x264 |
RegSetValueExW | 0x0 | 0x449004 | 0x5ca38 | 0x5bc38 | 0x2a9 |
RegOpenKeyExW | 0x0 | 0x449008 | 0x5ca3c | 0x5bc3c | 0x28c |
GetUserNameW | 0x0 | 0x44900c | 0x5ca40 | 0x5bc40 | 0x17b |
RegQueryValueExW | 0x0 | 0x449010 | 0x5ca44 | 0x5bc44 | 0x299 |
RegCloseKey | 0x0 | 0x449014 | 0x5ca48 | 0x5bc48 | 0x25b |
WININET.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x4491c4 | 0x5cbf8 | 0x5bdf8 | 0xce |
HttpOpenRequestW | 0x0 | 0x4491c8 | 0x5cbfc | 0x5bdfc | 0x79 |
HttpSendRequestW | 0x0 | 0x4491cc | 0x5cc00 | 0x5be00 | 0x82 |
InternetCloseHandle | 0x0 | 0x4491d0 | 0x5cc04 | 0x5be04 | 0x95 |
InternetOpenW | 0x0 | 0x4491d4 | 0x5cc08 | 0x5be08 | 0xc9 |
InternetConnectW | 0x0 | 0x4491d8 | 0x5cc0c | 0x5be0c | 0x9c |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
wincproc.exe | 2 | 0x01210000 | 0x01274FFF | Relevant Image |
![]() |
32-bit | 0x01231E98 |
![]() |
![]() |
...
|
wincproc.exe | 2 | 0x01210000 | 0x01274FFF | Final Dump |
![]() |
32-bit | 0x01216000 |
![]() |
![]() |
...
|
wincproc.exe | 3 | 0x00B70000 | 0x00BD4FFF | Relevant Image |
![]() |
32-bit | 0x00B91E98 |
![]() |
![]() |
...
|
wincproc.exe | 3 | 0x00B70000 | 0x00BD4FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Razy.614482 |
Malicious
|
C:/Users/5p5NrGJn0jS HALPmcxz/ntuser.ini.bbadc | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Network/Connections/Pbk/_hiddenPbk/rasphone.pbk.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Crypto/CLICK_HERE-bbadc.txt | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0043-0409-1000-0000000FF1CE}-C/Office32MUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0043-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0044-0409-1000-0000000FF1CE}-C/InfoPathMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0044-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0054-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/3oLcm6xOQxXk.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/4B12ndQiMxQxLwv.rtf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/4z 1gVfbGu.jpg.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/5tu LK5.mkv.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/6UPzAC.pdf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/AqhuJpi-FF6-ZAMnba.pptx.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/CaAnX3.swf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/CDAyh hTdGVqv.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/DkJmDxet.avi.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Fdp33brp5gORa.pdf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/fGHCXR3ckOQzXAN.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/FzQBAJJKzwdegbF.mp3.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Gk6KSt29.png.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/GP1f_5GF-l2jnwQ_.mkv.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/gT ZLIcp2W5 Lp.pptx.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/iH22Q1om LORnF8i.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/iqPiHJ4UhVOxR.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/KlCNtHcsKz5Io.odp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/lCbweFIWv.swf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/N5fOA3zauw5c3cXsg1.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/nXY qL_Dh.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/pH6g07N1YvbOjjf5I.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/PJ8Xt-GdBuI-d.png.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/qBU7xep6q30.avi.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/SGJ19HBDqxN8rmFw-Sz.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Sy712WLmR.odp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/THqkTiQY4tqORCNFYEG.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/tjvJOWe1FZ.flv.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Tz76RdBd.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/wARmWpDohs.odt.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/wG _q_tzkKs8kUGe5.jpg.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/xas2uLpyTtit_w.pptx.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/XW55KCA.mkv.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/z6KSlIX1IV6wL21J.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/_hpZVEHC2.mp4.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Document Building Blocks/1033/14/Built-In Building Blocks.dotx.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/MS Project/14/1033/Global.MPT.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Office/MSO1033.acl.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Publisher Building Blocks/ContentStore.xml.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/UProof/CUSTOM.DIC.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/9XNpC9Q.mp4.bbadc | Dropped File | Stream |
Unknown
|
...
|
»