gfvrib.exe
Created 6 years ago
VMRay Threat Identifiers (10 rules, 4097 matches)
Severity | Category | Operation | Count | Classification | |
---|---|---|---|---|---|
5/5 | File System | Encrypts content of user files | 1 | Ransomware | |
5/5 | Reputation | Known malicious file | 1 | Trojan | |
3/5 | File System | Possibly drops ransom note files | 1 | Ransomware | |
2/5 | Anti Analysis | Resolves APIs dynamically to possibly evade static detection | 1 | - | |
1/5 | Process | Creates system object | 1 | - | |
1/5 | File System | Modifies application directory | 6364 | - | |
1/5 | File System | Creates an unusually large number of files | 1 | - | |
1/5 | Network | Checks external IP address | 1 | - | |
1/5 | Network | Connects to HTTP server | 2 | - | |
1/5 | Static | Unparsable sections in file | 1 | - |
Screenshots
MITRE ATT&CK™ Matrix - Windows
Sample Information
ID | #165801 |
MD5 | |
SHA1 | |
SHA256 | |
SSDeep | |
ImpHash | |
Filename | gfvrib.exe |
File Size | 246.00 kB |
Sample Type | Windows Exe (x86-32) |
Analysis Information
Creation Time: | 2019-09-02 23:09 (UTC+) |
Analysis Duration: | 00:03:10 |
Number of Monitored Processes | 1 |
Execution Successful | ![]() |
Reputation Enabled | ![]() |
WHOIS Enabled | ![]() |
Local AV Enabled | ![]() |
YARA Enabled | ![]() |
Number of AV Matches | 0 |
Number of YARA Matches | 0 |
Termination Reason | Maximum binlog size reached |