Try VMRay Platform
Malicious
Classifications

Ransomware Wiper

Threat Names

-

Remarks (2/3)

(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.

(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.

(0x0200000E): The overall sleep time of all monitored processes was truncated from "26 minutes, 38 seconds" to "10 seconds" to reveal dormant functionality.

VMRay Threat Identifiers (25 rules, 31 matches)

ScoreCategoryOperationCountClassification
5/5
User Data ModificationDeletes user files1Wiper
5/5
User Data ModificationAppends new extensions to many filenames1Ransomware
4/5
Defense EvasionTries to disable antivirus software2-
4/5
ReputationMalicious file detected via reputation1-
4/5
YARAMalicious content matched by YARA rules2-
3/5
Anti AnalysisTries to evade debugger1-
3/5
System ModificationDisables a crucial system service2-
3/5
User Data ModificationPossibly drops ransom note files1Ransomware
3/5
Anti AnalysisModifies native system functions1-
2/5
Anti AnalysisDelays execution1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Windows Management Instrumentation
Persistence
Registry Run Keys / Startup Folder
Service Registry Permissions Weakness
New Service
Privilege Escalation
Service Registry Permissions Weakness
New Service
Defense Evasion
Disabling Security Tools
Hidden Window
Modify Registry
Software Packing
Masquerading
File System Logical Offsets
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Data Encrypted for Impact
Data Destruction
Service Stop
Defacement

Sample Information

ID#10499859
MD5
0f878dfe1534672d7236b1268ff7a8df
SHA1
05f04be9b9afc3f5823c5ed6f4911f25d7a464c5
SHA256
7bb3816e58d8a956b13aac53f75f762442a9849cd0ab324be6334e9a5e4b718f
SSDeep
3072:U6glyuxE4GsUPnliByocWep6muEEeh2T9IBw6P:U6gDBGpvEByocWeMnDu2T9IBt
ImpHash
41fb8cb2943df6de998b35a9d28668e8
File Name7bb3816e58d8a956b13aac53f75f762442a9849cd0ab324be6334e9a5e4b718f.exe
File Size153.50 KB
Sample TypeWindows Exe (x86-32)

Analysis Information

Creation Time2024-05-24 23:05 (UTC+)
Analysis Duration00:04:00
Termination ReasonTimeout
Number of Monitored Processes37
Execution Successful
Reputation Enabled
Built-in AV Enabled
Number of AV Matches0
YARA Enabled
Number of YARA Matches2
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image