VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Mal/Generic-S
|
bild.exe
Windows Exe (x86-32)
Created at 2020-03-26T14:44:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bild.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x457840 |
Size Of Code | 0x11d200 |
Size Of Initialized Data | 0x16000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11d0be | 0x11d200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.11 |
.rdata | 0x51f000 | 0x132817 | 0x132a00 | 0x11d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.72 |
.data | 0x652000 | 0x2ac18 | 0x16000 | 0x250000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.08 |
.idata | 0x67d000 | 0x3aa | 0x400 | 0x266000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.53 |
.symtab | 0x67e000 | 0x4 | 0x200 | 0x266400 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
kernel32.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x652020 | 0x27d312 | 0x266312 | 0x0 |
WriteConsoleW | 0x0 | 0x652024 | 0x27d316 | 0x266316 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x652028 | 0x27d31a | 0x26631a | 0x0 |
WaitForSingleObject | 0x0 | 0x65202c | 0x27d31e | 0x26631e | 0x0 |
VirtualQuery | 0x0 | 0x652030 | 0x27d322 | 0x266322 | 0x0 |
VirtualFree | 0x0 | 0x652034 | 0x27d326 | 0x266326 | 0x0 |
VirtualAlloc | 0x0 | 0x652038 | 0x27d32a | 0x26632a | 0x0 |
SwitchToThread | 0x0 | 0x65203c | 0x27d32e | 0x26632e | 0x0 |
SuspendThread | 0x0 | 0x652040 | 0x27d332 | 0x266332 | 0x0 |
SetWaitableTimer | 0x0 | 0x652044 | 0x27d336 | 0x266336 | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x652048 | 0x27d33a | 0x26633a | 0x0 |
SetProcessPriorityBoost | 0x0 | 0x65204c | 0x27d33e | 0x26633e | 0x0 |
SetEvent | 0x0 | 0x652050 | 0x27d342 | 0x266342 | 0x0 |
SetErrorMode | 0x0 | 0x652054 | 0x27d346 | 0x266346 | 0x0 |
SetConsoleCtrlHandler | 0x0 | 0x652058 | 0x27d34a | 0x26634a | 0x0 |
ResumeThread | 0x0 | 0x65205c | 0x27d34e | 0x26634e | 0x0 |
PostQueuedCompletionStatus | 0x0 | 0x652060 | 0x27d352 | 0x266352 | 0x0 |
LoadLibraryA | 0x0 | 0x652064 | 0x27d356 | 0x266356 | 0x0 |
LoadLibraryW | 0x0 | 0x652068 | 0x27d35a | 0x26635a | 0x0 |
SetThreadContext | 0x0 | 0x65206c | 0x27d35e | 0x26635e | 0x0 |
GetThreadContext | 0x0 | 0x652070 | 0x27d362 | 0x266362 | 0x0 |
GetSystemInfo | 0x0 | 0x652074 | 0x27d366 | 0x266366 | 0x0 |
GetSystemDirectoryA | 0x0 | 0x652078 | 0x27d36a | 0x26636a | 0x0 |
GetStdHandle | 0x0 | 0x65207c | 0x27d36e | 0x26636e | 0x0 |
GetQueuedCompletionStatus | 0x0 | 0x652080 | 0x27d372 | 0x266372 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x652084 | 0x27d376 | 0x266376 | 0x0 |
GetProcAddress | 0x0 | 0x652088 | 0x27d37a | 0x26637a | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x65208c | 0x27d37e | 0x26637e | 0x0 |
GetConsoleMode | 0x0 | 0x652090 | 0x27d382 | 0x266382 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x652094 | 0x27d386 | 0x266386 | 0x0 |
ExitProcess | 0x0 | 0x652098 | 0x27d38a | 0x26638a | 0x0 |
DuplicateHandle | 0x0 | 0x65209c | 0x27d38e | 0x26638e | 0x0 |
CreateThread | 0x0 | 0x6520a0 | 0x27d392 | 0x266392 | 0x0 |
CreateIoCompletionPort | 0x0 | 0x6520a4 | 0x27d396 | 0x266396 | 0x0 |
CreateEventA | 0x0 | 0x6520a8 | 0x27d39a | 0x26639a | 0x0 |
CloseHandle | 0x0 | 0x6520ac | 0x27d39e | 0x26639e | 0x0 |
AddVectoredExceptionHandler | 0x0 | 0x6520b0 | 0x27d3a2 | 0x2663a2 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bild.exe | 1 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x00457875 |
![]() |
![]() |
...
|
bild.exe | 1 | 0x00400000 | 0x0067EFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\Windows/Professional.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
File Reputation Information
»
Severity |
Whitelisted
|
C:\Windows/WindowsUpdate.log | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/bFyckmHxJ9S 6Zo n.m4a | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/BTEKktQ9VWYDLS.avi | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/cfXt.wav | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/SxEogh _mSwjC_Itw78.gif | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/woR3YnVY9vb.wav | Modified File | Stream |
Whitelisted
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/yPINHpfZcTmXK7by_yKT.avi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\/BOOTSECT.BAK_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//2FztngZG.mp3_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//5JiXkvp5.avi_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//7FCvFAmgT0_OKG636K4.mkv_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//beCeKzB1ilxBmpPiMC0.gif_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//desktop.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//D82pMr_gWfXCwM-g3.ods_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
.//sGAWhOSwfvCXpB.mkv_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot/BOOTSTAT.DAT_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files/desktop.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)/desktop.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users/desktop.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/bfsvc.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/DtcInstall.log_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/fveupdate.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot/memtest.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/hh.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/mib.bin_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/msdfmap.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/PFRO.log_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/Professional.xml_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/setupact.log_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/splwow64.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/Starter.xml_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/system.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/TSSysprep.log_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/twain.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\regedit.exe_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Windows/vbaddin.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/win.ini_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/WindowsShell.Manifest_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/winhlp32.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/WindowsUpdate.log_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/write.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/bFyckmHxJ9S 6Zo n.m4a_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/BTEKktQ9VWYDLS.avi_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/cfXt.wav_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows/WMSysPr9.prx_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/SxEogh _mSwjC_Itw78.gif_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
./\K0uSMPjMxsWd8OPvjC/yPINHpfZcTmXK7by_yKT.avi_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\fi-FI/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\el-GR/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\boot\de-de\bootmgr.exe.mui_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts/wgl4_boot.ttf_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\boot\es-es\bootmgr.exe.mui_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ru-RU/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\sv-SE/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files/3dftp.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files/fpos.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pl-PL/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker/audiodepthconverter.ax_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker/directshowtap.ax_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker/offset.ax_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\DVD Maker/rtstreamsink.ax_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/iecompat.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/ieproxy.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/IEShims.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/jsdbgui.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer/JSProfilerCore.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft synchronization services\loves.exe_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Uninstall Information/far.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\windows defender\mpcommu.dll_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Defender/MpEvMsg.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\windows defender\mpclient.dll_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Defender/MSASCui.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\windows defender\msmpres.dll_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Journal/jnwmon.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Journal/PDIALOG.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Journal/spcwin.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Mail/oeimport.dll_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Windows Mail/wab.exe_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\windows mail\wabmig.exe_id_2620738370_bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\da-DK/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\cs-CZ/bootmgr.exe.mui_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot/BCD.LOG2_ID_2620738370_Bossi_tosi@protonmail.com.google | Dropped File | Unknown |
Not Queried
|
...
|
»