Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S
Dynamic Analysis Report
Created on 2022-11-23T11:40:36+00:00
9455b7fcf93f0a5a6f9c099fbe938f5a9169f8d3dcc83833aa2c0f903518cfa3.exe
Windows Exe (x86-64)
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\9455b7fcf93f0a5a6f9c099fbe938f5a9169f8d3dcc83833aa2c0f903518cfa3.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x140000000 |
Entry Point | 0x14001A2E1 |
Size Of Code | 0x00025E00 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_AMD64 |
Compile Timestamp | 1970-01-01 01:00 (UTC+1) |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x140001000 | 0x00025D43 | 0x00025E00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.37 |
.rdata | 0x140027000 | 0x00000EF0 | 0x00001000 | 0x00026200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.55 |
.data | 0x140028000 | 0x000021B8 | 0x00001C00 | 0x00027200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.9 |
.pdata | 0x14002B000 | 0x000001C8 | 0x00000200 | 0x00028E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.16 |
.reloc | 0x14002C000 | 0x0000003C | 0x00000200 | 0x00029000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.89 |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
9455b7fcf93f0a5a6f9c099fbe938f5a9169f8d3dcc83833aa2c0f903518cfa3.exe | 1 | 0x7FF7115F0000 | 0x7FF71161CFFF | Relevant Image |
![]() |
64-bit | 0x7FF7115F107B |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x00020FFF | First Execution |
![]() |
64-bit | 0x00020080 |
![]() |
...
|
ntdll.dll | 1 | 0x7FFD0D950000 | 0x7FFD0DB10FFF | First Execution |
![]() |
64-bit | 0x7FFD0D9F5280 |
![]() |
...
|
ntdll.dll | 1 | 0x7FFD0D950000 | 0x7FFD0DB10FFF | Content Changed |
![]() |
64-bit | 0x7FFD0D97EB00 |
![]() |
...
|
9455b7fcf93f0a5a6f9c099fbe938f5a9169f8d3dcc83833aa2c0f903518cfa3.exe | 1 | 0x7FF7115F0000 | 0x7FF71161CFFF | Final Dump |
![]() |
64-bit | - |
![]() |
...
|
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\proplusww.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00a1-0409-0000-0000000ff1ce}-c\onotelr.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\owow64ww.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.es\proof.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\propsww2.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.fr\proof.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-001b-0409-0000-0000000ff1ce}-c\wordlr.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0115-0409-0000-0000000ff1ce}-c\officelr.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0018-0409-0000-0000000FF1CE}-C\PptLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0016-0409-0000-0000000FF1CE}-C\ExcelLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-001A-0409-0000-0000000FF1CE}-C\OutlkLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\Office64WW.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0044-0409-0000-0000000FF1CE}-C\InfLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0019-0409-0000-0000000FF1CE}-C\PubLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\outlookmui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0019-0409-0000-0000000FF1CE}-C\PublisherMUI.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-001b-0409-0000-0000000ff1ce}-c\wordmui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0018-0409-0000-0000000ff1ce}-c\powerpointmui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0090-0409-0000-0000000ff1ce}-c\dcfmui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0044-0409-0000-0000000FF1CE}-C\InfoPathMUI.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00ba-0409-0000-0000000ff1ce}-c\groovemui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proof.en\proof.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00E1-0409-0000-0000000FF1CE}-C\OSMMUI.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0116-0409-1000-0000000ff1ce}-c\office64mui.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proofing.msi.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00BA-0409-0000-0000000FF1CE}-C\GrooveLR.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0090-0409-0000-0000000FF1CE}-C\DCFMUI.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0011-0000-0000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0115-0409-0000-0000000FF1CE}-C\branding.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\proplusww.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00e1-0409-0000-0000000ff1ce}-c\osmmui.cab.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0115-0409-0000-0000000ff1ce}-c\officemui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0011-0000-0000-0000000ff1ce}-c\office64ww.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\Boot\bg-BG\d0nut.html | Dropped File | HTML |
Clean
|
...
|
»
c:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-001a-0409-0000-0000000ff1ce}-c\outlookmui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-001B-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0016-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00A1-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-001B-0409-0000-0000000FF1CE}-C\WordMUI.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0018-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00e1-0409-0000-0000000ff1ce}-c\setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0090-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0019-0409-0000-0000000FF1CE}-C\Setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0044-0409-0000-0000000ff1ce}-c\setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0019-0409-0000-0000000ff1ce}-c\publishermui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0018-0409-0000-0000000ff1ce}-c\powerpointmui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00ba-0409-0000-0000000ff1ce}-c\setup.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00E2-0409-0000-0000000FF1CE}-C\OSMUXMUI.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0044-0409-0000-0000000ff1ce}-c\infopathmui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-0090-0409-0000-0000000ff1ce}-c\dcfmui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-00BA-0409-0000-0000000FF1CE}-C\GrooveMUI.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-00e1-0409-0000-0000000ff1ce}-c\osmmui.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\msocache\all users\{90160000-002c-0409-0000-0000000ff1ce}-c\proofing.xml.d0nut | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\java\jre1.8.0_171\lib\images\cursors\cursors.properties.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\ext\cldrdata.jar.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\images\cursors\win32_LinkNoDrop32x32.gif.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\jfr\profile.jfc.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\java\jre1.8.0_171\lib\jfr\default.jfc.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\ext\jaccess.jar.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\java\jre1.8.0_171\lib\images\cursors\invalid32x32.gif.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\security\blacklist.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\java\jre1.8.0_171\lib\images\cursors\win32_linkdrop32x32.gif.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\Program Files\Java\jre1.8.0_171\lib\ext\jfxrt.jar.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\java\jre1.8.0_171\lib\images\cursors\win32_copydrop32x32.gif.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\office16\cultures\office.odf.d0nut | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\common files\services\verisign.bmp.d0nut | Dropped File | Empty |
Clean
|
...
|
»
\\?\C:\MSOCache\All Users\{90160000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.xml.d0nut | Modified File | Stream |
Clean
|
...
|
»