Try VMRay Platform

Remarks (1/1)

(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 hours, 20 minutes, 36 seconds" to "4 seconds" to reveal dormant functionality.

Remarks

(0x0200005D): 986 additional dumps with the reason "Content Changed" and a total of 2306 MB were skipped because the respective maximum limit was reached.

Filters:
File Name Category Type Verdict Actions
C:\Users\OqXZRaykm\Desktop\defOff.exe Sample File Binary
Malicious
»
Also Known As defOff.exe (Accessed File)
MIME Type application/vnd.microsoft.portable-executable
File Size 2.58 MB
MD5 6b250d3527d2946de16a9b46ec93d9da Copy to Clipboard
SHA1 c45d245e1be62def9981e7657bf226d53c19ce80 Copy to Clipboard
SHA256 60a10c66c1b2af4c38ca4f1c8aa496733f571ddace185d9185e3cbdb93880e81 Copy to Clipboard
SSDeep 49152:53GwcsI0vqktNAEmv+3SSHI/Msjz0DX36CeIOfM3Ybc:53GsIc1bApmCSo/MsPiaC3OfM3Yb Copy to Clipboard
ImpHash 2eabe9054cad5152567f0699947a2c5b Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x0069E000
Size Of Code 0x00002400
Size Of Initialized Data 0x00000800
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2023-10-15 17:58 (UTC)
Version Information (11)
»
Comments -
CompanyName -
FileDescription defOff
FileVersion 1.0.0.0
InternalName defOff.exe
LegalCopyright Copyright © 2023
LegalTrademarks -
OriginalFilename defOff.exe
ProductName defOff
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0
Sections (6)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
0x00402000 0x00004000 0x00001200 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 7.78
.rsrc 0x00406000 0x0000059C 0x00000600 0x00003200 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 4.04
.idata 0x00408000 0x00002000 0x00000200 0x00003800 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.93
fstwwbmp 0x0040A000 0x00292000 0x00290200 0x00003A00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 6.54
ximdardy 0x0069C000 0x00002000 0x00000400 0x00293C00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 6.15
.taggant 0x0069E000 0x00004000 0x00002200 0x00294000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.78
Imports (1)
»
kernel32.dll (1)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
lstrcpy - 0x00408034 0x0000802C 0x0000382C 0x00000000
Memory Dumps (48)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
defoff.exe 1 0x00750000 0x009F1FFF First Execution False 32-bit 0x009EE000 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075D15B False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075E68B False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007604ED False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007D3628 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0083C3C7 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008C8425 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075DE0F False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008CB000 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008D2DDA False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008D7BBC False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075E000 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008D3684 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008D2E42 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008DC7EE False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075DE0F False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008E4003 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007EC450 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007CCBEA False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007A360F False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x00776AA1 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0079D000 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008ED28C False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008C3000 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008F5167 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008ED292 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x007EADFB False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x0075F08B False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008FC83F False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x008FDB6A False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x00909199 False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x009152CD False
defoff.exe 1 0x00750000 0x009F1FFF Content Changed False 32-bit 0x00915000 False
user32.dll 1 0x764E0000 0x76673FFF First Execution False 32-bit 0x765058D0 False
advapi32.dll 1 0x767D0000 0x76848FFF First Execution False 32-bit 0x767EF320 False
ntdll.dll 1 0x77590000 0x77731FFF First Execution False 32-bit 0x775D52C0 False
shlwapi.dll 1 0x76E80000 0x76EC4FFF First Execution False 32-bit 0x76E9A0A0 False
mscoree.dll 1 0x700F0000 0x70141FFF First Execution False 32-bit 0x7011F100 False
mscoreei.dll 1 0x6FB70000 0x6FBFCFFF First Execution False 32-bit 0x6FB7FA20 False
kernel.appcore.dll 1 0x75140000 0x7514EFFF First Execution False 32-bit 0x75143A50 False
version.dll 1 0x74AE0000 0x74AE7FFF First Execution False 32-bit 0x74AE15C0 False
clr.dll 1 0x6F3C0000 0x6FB6FFFF First Execution False 32-bit 0x6F5317C0 False
rpcrt4.dll 1 0x76420000 0x764D9FFF First Execution False 32-bit 0x76449507 False
combase.dll 1 0x757C0000 0x75A3FFFF First Execution False 32-bit 0x7583CD05 False
clrjit.dll 1 0x6DE70000 0x6DEF8FFF First Execution False 32-bit 0x6DE751D0 False
sechost.dll 1 0x76180000 0x761F4FFF First Execution False 32-bit 0x76197ABD False
buffer 1 0x045F0000 0x045F0FFF Marked Executable False 32-bit - False
defoff.exe 1 0x00750000 0x009F1FFF Process Termination False 32-bit - False
C:\Users\OqXZRaykm\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\defOff.exe.log Dropped File Unknown
Clean
»
MIME Type application/csv
File Size 226 Bytes
MD5 cc70991fb12e3e77e295063f27958932 Copy to Clipboard
SHA1 6750b1c1704d922608cebcef4b171f99fa26e224 Copy to Clipboard
SHA256 19f230576e8680f451e9e4aee6ec67c16a49c01cdebde0979bc26c9361253281 Copy to Clipboard
SSDeep 6:Q3La/xw5DLIP12MUAvvR+uTL285MbQQPFv:Q3La/KDLI4MWuPgbQWv Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image