VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Trojan.GenericKD.33707328
Mal/Generic-S
|
ctfmon.exe
Windows Exe (x86-32)
Created at 2020-04-27T07:41:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41a0e2 |
Size Of Code | 0x18200 |
Size Of Initialized Data | 0x19000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-22 03:25:01+00:00 |
Version Information (8)
»
Assembly Version | 1.0.0.0 |
FileDescription | ctfmon |
FileVersion | 1.0.0.0 |
InternalName | ctfmon.exe |
LegalCopyright | Copyright © 2020 |
OriginalFilename | ctfmon.exe |
ProductName | ctfmon |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x180e8 | 0x18200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.14 |
.reloc | 0x41c000 | 0xc | 0x200 | 0x18400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
.rsrc | 0x41e000 | 0xde0 | 0xe00 | 0x18600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.94 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1a0b0 | 0x182b0 | 0x0 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ctfmon.exe | 1 | 0x00770000 | 0x0078FFFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.33707328 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_ol02zsle.dbs.psm1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\816ef3ee-d423-4062-b4a8-4107c0ff2138.lnk | Dropped File | Shortcut |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0NkTTcPD2Gs.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0U9qeqZ.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1QbrVzP.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\8MpM.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\CYj6oMcAbFElTEuYIb.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HxC02D.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HzkAh7aeX.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\k1zaSpZFmZq4jwr b.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\l7HcwF09tCpP_6VimeqC.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\m4jG_OaBVfmRUZ-7b.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\PSbMxGzUnWWSJCzs2csc.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\qSU_EPgkC.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\s-M AVO96.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\tg9hG.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\umDqDg7W39zYqe05.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\vf54Aj8.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\06y-LRDsdF.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\7ni c9g.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\dkciarLK.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\Fcdkj2 YJ1zmyajL.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\g9-mcdxhqihiwZ.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\IcU1YWILYLm_VpZL43O.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\JDqWN f2E.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\Jiz1j.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\K8fXuy.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\L4Jm-.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\lUVTp.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\m2oQ.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\uM4MUCefD0Wmz.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\v 68BszOBIs 8t.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\W1Pr_afv.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bmWV31z5uQ 5\_9FRra.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\518W5r-93.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\8U8eAAlY_V9XGp.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ADUOQhgblZC.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\An2XyJELftzrrda2Qi9Z.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\awjYBWWUUDv.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\DPDy.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EwLN28PIWgDe.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fko8QIWFn.doc.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\JAxyw3x-tJrrF.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OruO9Aw.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qh7qU7_Fer.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\T6TgyvPCgPe2UW.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\VqeC4xk8qQsfNx3.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\0tw tUuSH2WNk1z.ppt.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\1ckS1JjaF.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\qoNQhW\oqIOz6iz.doc.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\qoNQhW\PSAY1cgEX.pdf.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\qoNQhW\pwAyObt8RNfNX8YXKy4Y.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\qoNQhW\umbEdP0Ss9TgE S.xls.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\qoNQhW\Z37OH.xls.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\7i3o2-kfBOXqx54cu6.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\FabaBlRQZCjZVZLt12LF.doc.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\tJEck5lixY8n3t9o.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\1ripCiHS8\K5Tya1.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\1ripCiHS8\RWOs95.ppt.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\1ripCiHS8\wEKSTaeByKw.doc.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\1ripCiHS8\zI o56T3ghe1br2qm.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C88ZZWLu 8ct2QXY\kJ4g3dOlN66IH-\1ripCiHS8\zQrp.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3V-VvdXRkr9VL9J3PcV.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\g1R1oG7uZJ RI9M6.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\LhOK75rd2Dc PWsth is.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oz1wxxjyP4gePV.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\p eJEJwq7NKXrtf.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\PpBwKL3XDYUwK.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tbQID kwf.xls.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tT1Tx.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\U-uxJFdWkC1M-wO6cUKB.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\uO MS9hVAQqXyw.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vZyE.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Y58zNJtwG3kek2x.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Yawl.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Z6uv3qRB.docx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\_USg.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\0gTzRzCE.pptx.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\iplOps-KE8gr.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\JsD_Y4AtT TUM6H.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\KfJv PgPqiI.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\MxjCd1y -YjbcjslQ2YC.png.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\p1AwM.gif.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\QkFjdZPZM.doc.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\s80jGWSaHv98JLm6C1bF.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xtTK\TBiGnuVHgHJy7oj1jnv.jpg.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user-192.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user-32.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user-40.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user-48.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user.bmp.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\guest.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\background.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\device\{8702d817-5aad-4674-9ef3-4d3decd87120}\watermark.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\device stage\device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.p4wn3d | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.P4WN3D | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\tmp.txt | Dropped File | Text |
Unknown
|
...
|
»