Created 3 years ago
a7f09cfde433f3d47fc96502bf2b623ae5e7626da85d0a0130dcd19d1679af9b.exe
VMRay Threat Identifiers (15 rules, 33 matches)
Score | Category | Operation | Count | Classification | |
---|---|---|---|---|---|
5/5 | User Data Modification | Modifies content of user files | 1 | Ransomware | |
5/5 | User Data Modification | Renames user files | 1 | Ransomware | |
5/5 | User Data Modification | Appends the same extension to many filenames | 1 | Ransomware | |
5/5 | Data Collection | Tries to read cached credentials of various applications | 1 | Spyware | |
4/5 | Reputation | Known malicious file | 1 | - | |
3/5 | User Data Modification | Possibly drops ransom note files | 1 | Ransomware | |
2/5 | Data Collection | Reads sensitive ftp data | 1 | - | |
2/5 | Data Collection | Reads sensitive mail data | 1 | - | |
2/5 | Data Collection | Reads sensitive browser data | 1 | - | |
1/5 | Privilege Escalation | Enables process privilege | 2 | - | |
Screenshots
MITRE ATT&CK™ Matrix - Windows
Sample Information
ID | #4194433 |
MD5 | |
SHA1 | |
SHA256 | |
SSDeep | |
ImpHash | |
File Name | a7f09cfde433f3d47fc96502bf2b623ae5e7626da85d0a0130dcd19d1679af9b.exe |
File Size | 26.00 KB |
Sample Type | Windows Exe (x86-32) |
Analysis Information
Creation Time | 2022-04-25 22:04 (UTC+) |
Analysis Duration | 00:04:00 |
Termination Reason | Timeout |
Number of Monitored Processes | 2 |
Execution Successful | |
Reputation Enabled | |
Built-in AV Enabled | |
Number of AV Matches | 0 |
YARA Enabled | |
Number of YARA Matches | 0 |