Malicious
Classifications
Downloader Exploit
Threat Names
Mal/HTMLGen-A
Dynamic Analysis Report
Created on 2023-08-15T06:03:24+00:00
Bank details.doc.rtf
RTF Document
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\Bank details.doc.rtf | Sample File | RTF |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Office Information
»
Document Content Snippet
»
40582139please click Enable editing from the yellow bar above.The independent auditors’ opinion says the financial statements are fairly stated in accordance with the basis of accounting used by your organization. So why are the auditors giving you that other letter In an audit of financial statements, professional standards require that auditors obtain an understanding of internal controls to the extent necessary to plan the audit. Auditors use this understanding of internal controls to assess the risk of material misstatement of the financial statements and to design appropriate audit procedures to minimize that risk.The definition of good internal controls is that they allow errors and other misstatements to be prevented or detected and corrected by (the nonprofit’s) employees in the normal course of performing their duties. If the auditors detect an unexpected material misstatement during your audit, it could indicate that your internal controls are not functioning properly. Conver |
C:\Users\kEecfMwgj\AppData\Roaming\nellyadh476528.exe | Downloaded File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Size Of Code | 0x0008F2DA |
Size Of Initialized Data | 0x00000A00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_AMD64 |
Compile Timestamp | 2023-08-12 16:06 (UTC+2) |
Version Information (9)
»
CompanyName | 耳麻考青羊閑吾 |
FileDescription | 羊閑吾貝 自風羊鼠而邑老 考馬自豕羽黽羊 自風自田自鬼自非自閑. |
FileVersion | 1.8.4.7 |
InternalName | 羊豸羽麥考黽而 |
LegalCopyright | © 2023 耳麻考青羊閑吾 . |
OriginalFilename | 羊龠羊馬老身自龍 |
ProductName | 羽四羊非而隹羽 |
ProductVersion | 1.8.4.7 |
Comments | 至辵自走老鹿吾革 考邑羽金 吾目老二 至九至鬼 老田羽隹羊四 自早耳鹿考馬 老十自鳥老麻羽. |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x0008F2DA | 0x0008F400 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 8.0 |
.rsrc | 0x00492000 | 0x00000974 | 0x00000A00 | 0x0008F600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.96 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
nellyadh476528.exe | 3 | 0x00D60000 | 0x00DF3FFF | Relevant Image | 64-bit | - |
...
|
||
buffer | 3 | 0x003C0000 | 0x003C1FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 3 | 0x02319928 | 0x0231992A | Marked Executable | 64-bit | - |
...
|
||
nellyadh476528.exe | 3 | 0x00D60000 | 0x00DF3FFF | Process Termination | 64-bit | - |
...
|