VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Gen:Heur.Ransom.REntS.Gen.1
|
GUkwRkMToehNH8CZ.exe
Windows Exe (x86-32)
Created at 2020-12-21T07:04:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\GUkwRkMToehNH8CZ.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x54c4aa |
Size Of Code | 0x14a600 |
Size Of Initialized Data | 0x1800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2100-02-20 19:19:52+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WindowsFormsApp1 |
FileVersion | 1.0.0.0 |
InternalName | WindowsFormsApp1.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | WindowsFormsApp1.exe |
ProductName | WindowsFormsApp1 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x14a4b0 | 0x14a600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.98 |
.rsrc | 0x54e000 | 0x1438 | 0x1600 | 0x14a800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.8 |
.reloc | 0x550000 | 0xc | 0x200 | 0x14be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x14c47f | 0x14a67f | 0x0 |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
gukwrkmtoehnh8cz.exe | 1 | 0x00070000 | 0x001C1FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x049E3000 | 0x049E4FFF | First Execution |
![]() |
32-bit | 0x049E3D8E |
![]() |
![]() |
...
|
buffer | 1 | 0x02112000 | 0x02112FFF | First Execution |
![]() |
32-bit | 0x02112053 |
![]() |
![]() |
...
|
buffer | 1 | 0x02112000 | 0x02112FFF | Content Changed |
![]() |
32-bit | 0x02112275 |
![]() |
![]() |
...
|
gukwrkmtoehnh8cz.exe | 1 | 0x00070000 | 0x001C1FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
Malicious
|
C:\Users\FD1HVy\Desktop\0Mnb.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\2GIJ.wav.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3n8W.ods.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\5eck_.swf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6McAIlu.flv.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6TA_p.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\b25tnbE7E9J_0.avi.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DNJ0jBHn-o_ZP8Vg6.odt.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dYdI-w6n3_m3jFmc.avi.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\fsBK-C-.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\gpuqXEpWWbQue.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Gqx6hadX8BA.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4M-h.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7Z 0lVLaokIpDMbCn.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ajP0XObNv_kd.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GUkwRkMToehNH8CZ.exe.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ALOYj.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bFv5D.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\fQx5SEtSbjG_Xd.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ft Ut.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\g02_GrvIku5VLUm6A.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\lGSgSxh.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\MzCDKn.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oK0Zcaq.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ou71Z.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rUJEpUQXIHItPk4CRYU5.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SfhIstnkvDxRXKXB3.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\TEMq1zcwczIu.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Un3qj.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\WBiG1iVen RrT.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\WZ6l-ufacjI UwQqXuT.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ym4AyOtD4LU2hVs.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_yu8ubor_1hWM.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\9Ez8l2YWj9H2Ap_.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\g TQCzcEK.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\Mhhs6d_oyhmZHDXHD4D.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\NFEXwxsvTFrnNxmB.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\PeOTIWfGxG0.gif.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\PmC02kFDILUQuzmf2.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\TrWLdnhAjVLLnMll.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\W7ygSWnKW2.bmp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\wZ9yPnB0.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\xTWFi5Z02m.png.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\yVagKL85d9TybhDvL.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\B0Zd\zv435yj.jpg.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Camera Roll\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Saved Pictures\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\-NfmAFsZPq_z.doc.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\4BdAogwesXfT1I405G1.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5 Pw2hm5wA.rtf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\50rlfcTzJyiex7_.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\a-wGo AGT.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\BG9j.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\c02Ledr_gXGZy4xb4Y4.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Cd3SMNbx.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\F1FyTmwO.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FMlO.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gjlGum9 _Ee85bqcuUI.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Gzhhv.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hSyH_j.pps.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iYXTlnvoNiNy.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jDLzaKs.rtf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\mDxbgSUyUSVOLd.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\P2MPoRKsx0l.pps.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pwafdbOk.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\R2BfZDNyzrms2OQqw.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\RW-I958R_YAEhKgr7.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\SF9WY2B71.pps.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\wJIi77j.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Y mk8du6Lt_hcV-.rtf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_8kLSgjP-Ebcj8bmjSKn.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\9HOg7Qvo.ots.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\a2ORU-m.rtf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\DsN0QHJj3yvcaFMDtxvL.ots.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\K958l-gmyNZkTre.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\naJHMT6vCuHMZmL-V.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\x3SOUM5XwTMTKSLPF.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\-ZCoSfi9aHv3nxat.ots.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\6jU_CaTcI-H.ppt.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\JZDvMWcBq.pps.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\lh w.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\mekfDw-S2.odt.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\oxfEj043P3khkhGCEmHR.xls.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\ZmrW.csv.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\5G6nJ.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\A2VqlAymxq-rH_GUk1.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\EScyXdAY.ots.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\fdCV-csWoZ.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\HIt_WPbB.docx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\oXNgj4sqwj4kA1rNWim.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\vJwj52gbptJ6vVAm8.rtf.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\6hFt.odt.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\B4Df-puxZmRH9ptlw.odp.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\eBCY2 K6.pptx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\pIH7NEBTTQo2dWf.odt.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\QZ n.doc.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\YRQqvwBEqiPpZLuQma.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\E4FJy\45zW0fA4vU Ca6HCIUG\cpFN15-nC 1m7\GpDdy\_C88c4pdIYtfHMPwk.xlsx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\My Shapes\desktop.ini.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\My Shapes\Favorites.vssx.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico.jcrypt | Dropped File | Stream |
Unknown
|
...
|
»