Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S
Dynamic Analysis Report
Created on 2025-03-28T06:30:12+00:00
4aa0392fa085affb4a7c91cd107fe3d2.exe
Windows Exe (x86-64)
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "46 minutes, 58 seconds" to "40 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 2 dump(s) were skipped because they exceeded the maximum dump size of 16 MB. The largest one was 16 MB.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\OqXZRaykm\Desktop\4aa0392fa085affb4a7c91cd107fe3d2.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00458B20 |
Size Of Code | 0x0022C800 |
Size Of Initialized Data | 0x00033600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_AMD64 |
Compile Timestamp | 1970-01-01 01:00 (UTC+1) |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0022C6C8 | 0x0022C800 | 0x00000600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.92 |
.rdata | 0x0062E000 | 0x00338F4A | 0x00339000 | 0x0022CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.87 |
.data | 0x00967000 | 0x00053DB8 | 0x00033600 | 0x00565E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.41 |
.idata | 0x009BB000 | 0x00000392 | 0x00000400 | 0x00599400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.99 |
.symtab | 0x009BC000 | 0x00000004 | 0x00000200 | 0x00599800 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
KERNEL32.DLL (31)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | - | 0x00967000 | 0x00567000 | 0x00565E00 | 0x00000000 |
WriteConsoleW | - | 0x00967008 | 0x00567008 | 0x00565E08 | 0x00000000 |
WaitForSingleObject | - | 0x00967010 | 0x00567010 | 0x00565E10 | 0x00000000 |
VirtualQuery | - | 0x00967018 | 0x00567018 | 0x00565E18 | 0x00000000 |
VirtualFree | - | 0x00967020 | 0x00567020 | 0x00565E20 | 0x00000000 |
VirtualAlloc | - | 0x00967028 | 0x00567028 | 0x00565E28 | 0x00000000 |
SwitchToThread | - | 0x00967030 | 0x00567030 | 0x00565E30 | 0x00000000 |
SetWaitableTimer | - | 0x00967038 | 0x00567038 | 0x00565E38 | 0x00000000 |
SetUnhandledExceptionFilter | - | 0x00967040 | 0x00567040 | 0x00565E40 | 0x00000000 |
SetProcessPriorityBoost | - | 0x00967048 | 0x00567048 | 0x00565E48 | 0x00000000 |
SetEvent | - | 0x00967050 | 0x00567050 | 0x00565E50 | 0x00000000 |
SetErrorMode | - | 0x00967058 | 0x00567058 | 0x00565E58 | 0x00000000 |
SetConsoleCtrlHandler | - | 0x00967060 | 0x00567060 | 0x00565E60 | 0x00000000 |
LoadLibraryA | - | 0x00967068 | 0x00567068 | 0x00565E68 | 0x00000000 |
LoadLibraryW | - | 0x00967070 | 0x00567070 | 0x00565E70 | 0x00000000 |
GetSystemInfo | - | 0x00967078 | 0x00567078 | 0x00565E78 | 0x00000000 |
GetSystemDirectoryA | - | 0x00967080 | 0x00567080 | 0x00565E80 | 0x00000000 |
GetStdHandle | - | 0x00967088 | 0x00567088 | 0x00565E88 | 0x00000000 |
GetQueuedCompletionStatus | - | 0x00967090 | 0x00567090 | 0x00565E90 | 0x00000000 |
GetProcessAffinityMask | - | 0x00967098 | 0x00567098 | 0x00565E98 | 0x00000000 |
GetProcAddress | - | 0x009670A0 | 0x005670A0 | 0x00565EA0 | 0x00000000 |
GetEnvironmentStringsW | - | 0x009670A8 | 0x005670A8 | 0x00565EA8 | 0x00000000 |
GetConsoleMode | - | 0x009670B0 | 0x005670B0 | 0x00565EB0 | 0x00000000 |
FreeEnvironmentStringsW | - | 0x009670B8 | 0x005670B8 | 0x00565EB8 | 0x00000000 |
ExitProcess | - | 0x009670C0 | 0x005670C0 | 0x00565EC0 | 0x00000000 |
DuplicateHandle | - | 0x009670C8 | 0x005670C8 | 0x00565EC8 | 0x00000000 |
CreateThread | - | 0x009670D0 | 0x005670D0 | 0x00565ED0 | 0x00000000 |
CreateIoCompletionPort | - | 0x009670D8 | 0x005670D8 | 0x00565ED8 | 0x00000000 |
CreateEventA | - | 0x009670E0 | 0x005670E0 | 0x00565EE0 | 0x00000000 |
CloseHandle | - | 0x009670E8 | 0x005670E8 | 0x00565EE8 | 0x00000000 |
AddVectoredExceptionHandler | - | 0x009670F0 | 0x005670F0 | 0x00565EF0 | 0x00000000 |
Memory Dumps (47)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
4aa0392fa085affb4a7c91cd107fe3d2.exe | 1 | 0x00400000 | 0x009BCFFF | Relevant Image |
![]() |
64-bit | 0x0043FB50 |
![]() |
...
|
buffer | 1 | 0x022BF000 | 0x022BFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x0205F000 | 0x0205FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x01E5E000 | 0x01E5FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x01C5F000 | 0x01C5FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x01A5F000 | 0x01A5FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x00BBD000 | 0x00BBFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x00180000 | 0x001BFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x001C0000 | 0x001E1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x001F0000 | 0x001FFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x00E90000 | 0x00E9FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x00EA0000 | 0x00EDFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x00EE0000 | 0x0103FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x01040000 | 0x0104FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x01060000 | 0x0185FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02060000 | 0x02081FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02090000 | 0x020B1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x022C0000 | 0x022E1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x022F0000 | 0x02311FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02320000 | 0x0232FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02330000 | 0x0236FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02370000 | 0x02391FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x023A0000 | 0x023C1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x023D0000 | 0x023F1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02400000 | 0x02421FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0x02430000 | 0x0246FFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000030000 | 0xC000031FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000058000 | 0xC000059FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000070000 | 0xC000077FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000084000 | 0xC000085FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000094000 | 0xC000095FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000096000 | 0xC000097FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0000BA000 | 0xC0000BBFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0000BE000 | 0xC0000BFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0000C0000 | 0xC0000C1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002DA000 | 0xC0002E1FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002E2000 | 0xC0002E3FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002E4000 | 0xC0002E5FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002E6000 | 0xC0002EDFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002EE000 | 0xC0002EFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0002F0000 | 0xC0002F7FFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000800000 | 0xC000BFFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC000C00000 | 0xC0013FFFFF | First Network Behavior |
![]() |
64-bit | - |
![]() |
...
|
4aa0392fa085affb4a7c91cd107fe3d2.exe | 1 | 0x00400000 | 0x009BCFFF | First Network Behavior |
![]() |
64-bit | 0x0061B460 |
![]() |
...
|
buffer | 1 | 0xC0002F8000 | 0xC000399FFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
...
|
4aa0392fa085affb4a7c91cd107fe3d2.exe | 1 | 0x00400000 | 0x009BCFFF | Final Dump |
![]() |
64-bit | - |
![]() |
...
|
buffer | 1 | 0xC0000D2000 | 0xC0001A9FFF | Image In Buffer |
![]() |
64-bit | - |
![]() |
...
|
C:\Program Files\Common Files\BuNzE64t q5MDF75eUE.jpg | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00458B20 |
Size Of Code | 0x0022C800 |
Size Of Initialized Data | 0x00033600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_AMD64 |
Compile Timestamp | 1970-01-01 01:00 (UTC+1) |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0022C6C8 | 0x0022C800 | 0x00000600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.92 |
.rdata | 0x0062E000 | 0x00338F4A | 0x00339000 | 0x0022CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.87 |
.data | 0x00967000 | 0x00053DB8 | 0x00033600 | 0x00565E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.41 |
.idata | 0x009BB000 | 0x00000392 | 0x00000400 | 0x00599400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.99 |
.symtab | 0x009BC000 | 0x00000004 | 0x00000200 | 0x00599800 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
KERNEL32.DLL (31)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | - | 0x00967000 | 0x00567000 | 0x00565E00 | 0x00000000 |
WriteConsoleW | - | 0x00967008 | 0x00567008 | 0x00565E08 | 0x00000000 |
WaitForSingleObject | - | 0x00967010 | 0x00567010 | 0x00565E10 | 0x00000000 |
VirtualQuery | - | 0x00967018 | 0x00567018 | 0x00565E18 | 0x00000000 |
VirtualFree | - | 0x00967020 | 0x00567020 | 0x00565E20 | 0x00000000 |
VirtualAlloc | - | 0x00967028 | 0x00567028 | 0x00565E28 | 0x00000000 |
SwitchToThread | - | 0x00967030 | 0x00567030 | 0x00565E30 | 0x00000000 |
SetWaitableTimer | - | 0x00967038 | 0x00567038 | 0x00565E38 | 0x00000000 |
SetUnhandledExceptionFilter | - | 0x00967040 | 0x00567040 | 0x00565E40 | 0x00000000 |
SetProcessPriorityBoost | - | 0x00967048 | 0x00567048 | 0x00565E48 | 0x00000000 |
SetEvent | - | 0x00967050 | 0x00567050 | 0x00565E50 | 0x00000000 |
SetErrorMode | - | 0x00967058 | 0x00567058 | 0x00565E58 | 0x00000000 |
SetConsoleCtrlHandler | - | 0x00967060 | 0x00567060 | 0x00565E60 | 0x00000000 |
LoadLibraryA | - | 0x00967068 | 0x00567068 | 0x00565E68 | 0x00000000 |
LoadLibraryW | - | 0x00967070 | 0x00567070 | 0x00565E70 | 0x00000000 |
GetSystemInfo | - | 0x00967078 | 0x00567078 | 0x00565E78 | 0x00000000 |
GetSystemDirectoryA | - | 0x00967080 | 0x00567080 | 0x00565E80 | 0x00000000 |
GetStdHandle | - | 0x00967088 | 0x00567088 | 0x00565E88 | 0x00000000 |
GetQueuedCompletionStatus | - | 0x00967090 | 0x00567090 | 0x00565E90 | 0x00000000 |
GetProcessAffinityMask | - | 0x00967098 | 0x00567098 | 0x00565E98 | 0x00000000 |
GetProcAddress | - | 0x009670A0 | 0x005670A0 | 0x00565EA0 | 0x00000000 |
GetEnvironmentStringsW | - | 0x009670A8 | 0x005670A8 | 0x00565EA8 | 0x00000000 |
GetConsoleMode | - | 0x009670B0 | 0x005670B0 | 0x00565EB0 | 0x00000000 |
FreeEnvironmentStringsW | - | 0x009670B8 | 0x005670B8 | 0x00565EB8 | 0x00000000 |
ExitProcess | - | 0x009670C0 | 0x005670C0 | 0x00565EC0 | 0x00000000 |
DuplicateHandle | - | 0x009670C8 | 0x005670C8 | 0x00565EC8 | 0x00000000 |
CreateThread | - | 0x009670D0 | 0x005670D0 | 0x00565ED0 | 0x00000000 |
CreateIoCompletionPort | - | 0x009670D8 | 0x005670D8 | 0x00565ED8 | 0x00000000 |
CreateEventA | - | 0x009670E0 | 0x005670E0 | 0x00565EE0 | 0x00000000 |
CloseHandle | - | 0x009670E8 | 0x005670E8 | 0x00565EE8 | 0x00000000 |
AddVectoredExceptionHandler | - | 0x009670F0 | 0x005670F0 | 0x00565EF0 | 0x00000000 |