Try VMRay Platform

VMRay Threat Identifiers (8 rules, 17 matches)

ScoreCategoryOperationCountClassification
5/5
YARAMalicious content matched by YARA rules6Ransomware
4/5
ReputationMalicious file detected via reputation1-
2/5
Network ConnectionAllows invalid SSL certificates1-
1/5
ObfuscationCreates a page with write and execute permissions4-
1/5
Hide TracksCreates process with hidden window1-
1/5
ObfuscationResolves API functions dynamically2-
1/5
ExecutionDrops PE file1-
1/5
ExecutionExecutes dropped PE file1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Hidden Window
Software Packing
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact

Sample Information

ID#9254320
MD5
64306135c8040ec8c2101e1f0bd6dc61
SHA1
d981fd91a3a31aa3891d98dfc569068145b8be77
SHA256
3a35de450f89eb21217d0a52df01dc796fd43bf5fb02c479d6b7b8503327209f
SSDeep
768:f6LsoEEeegiZPvEhHSG+gz5NQXtckstOOtEvwDpj/WaD3TUogs/VXpAPWRiV:f6QFElP6n+g9u9cvMOtEvwDpjnpVXzRE
ImpHash
bd2f03255beebcd07c02192dbb770be8
File Name7fq0PwBJkR1rhpBD.exe
File Size62.69 KB
Sample TypeWindows Exe (x86-32)

Analysis Information

Creation Time2025-04-03 00:04 (UTC+)
Analysis Duration00:04:00
Termination ReasonTimeout
Number of Monitored Processes2
Execution Successful
Reputation Enabled
Built-in AV Enabled
Number of AV Matches0
YARA Enabled
Number of YARA Matches14
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image