VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Worm
|
Threat Names: |
WannaCry
Generic.Ransom.Loli.8D00106D
Generic.Ransom.Loli.9863F222
|
software-launcher.exe
Windows Exe (x86-32)
Created at 2020-09-05T10:05:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\software-launcher.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x424b8e |
Size Of Code | 0x22c00 |
Size Of Initialized Data | 0x11000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-05 06:53:35+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | Microsoft Corporation |
FileDescription | System |
FileVersion | 1.0.0.0 |
InternalName | software-launcher.exe |
LegalCopyright | Copyright © Microsoft Corporation 2020 |
LegalTrademarks | - |
OriginalFilename | software-launcher.exe |
ProductName | System |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x22b9c | 0x22c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.84 |
.rsrc | 0x426000 | 0x10cb0 | 0x10e00 | 0x22e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.91 |
.reloc | 0x438000 | 0xc | 0x200 | 0x33c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x24b64 | 0x22d64 | 0x0 |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
software-launcher.exe | 1 | 0x00350000 | 0x00389FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00B11000 | 0x00B11FFF | First Execution |
![]() |
32-bit | 0x00B11000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00B11000 | 0x00B11FFF | Content Changed |
![]() |
32-bit | 0x00B11D87 |
![]() |
![]() |
...
|
buffer | 1 | 0x00B12000 | 0x00B12FFF | First Execution |
![]() |
32-bit | 0x00B12000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00B12000 | 0x00B12FFF | Content Changed |
![]() |
32-bit | 0x00B121B0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00B11000 | 0x00B11FFF | Content Changed |
![]() |
32-bit | 0x00B1105C |
![]() |
![]() |
...
|
buffer | 1 | 0x00ADB000 | 0x00ADBFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04A41000 | 0x04A42FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04A43000 | 0x04A44FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x07CA0000 | 0x07CA3FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
software-launcher.exe | 1 | 0x00350000 | 0x00389FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Loli.8D00106D |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
ransomware_windows_wannacry | WannaCry / WannaCryptor ransomware | Worm, Ransomware |
5/5
|
...
|
C:\Users\FD1HVy\Desktop\0GjDh.jpg.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3XrkXP.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6vMs sSe5shBJM4JwI.mkv.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\8I2X.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\A1kJ8aZMdwCT5 o.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\aiKeYWbHt1wT3oA.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DAiw493.mp4.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Gb83mX013La-khUZM.mp4.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hI1jNHlxGb.ppt.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kEy--vzdV9QfADXnMa.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\KFXfNEQ46rwzksz5j.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OAz_lPv4YRSscSFzZ.pptx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pj4LrBd4acn2MLQK.mkv.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\qABG1nnLkc.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\sG7r0dyBN.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3949S10Cvm.pptx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3KPK3d2n-VBnRKIF.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\9pCLq4mkMn.docx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\A8S69IoM5mx0b.rtf.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ak1foEa3vCPlvb.docx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ecd1Gkp7IDFh7Av.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eIGcZEJJ-5qaJj1GIdh2.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ix0_-E85lWgB.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jI_CG.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\kamSL3M1DL-stryf26BA.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OaPwgkrRJhJXTclj5w.pptx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Rc3gbAty.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\rimQ_RaO1MI HP3MXFsx.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\RSS-8.pptx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\SUrsPJWYfeM.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\u1IZyE5mbC.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Xs3mwy5fFpGMK.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\xYh-qhkG.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\hCQ4zDgBUP9vp5mwleAY.rtf.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\JipES.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\kMiNL4wvixI7ydk3Bvt.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\sV4MBIjci88ua4LER.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\Y0Zmzf.ppt.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\Y23KVV0MsNovXLR7.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\BqAT\1nS1aQxYU.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\BqAT\biQdLY7U6Ai.rtf.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrU-SyBX\QINP9eO5\kn3EA-JGuoQEwxtPn.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\0LhlaJ1QM40DJvej5.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\caaU5TgGx.pptx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\KMCxyp5o.odt.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\Lr g5689ZSM3RBBuvk.csv.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\q1TPd7rQ.xlsx.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\xszi4F.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z2ctz\y-3XV-DTzV84k.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7tcm.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SlzTbhsz.png.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ur4dy.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\VPfW-_NrvLHG E4.bmp.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xpaPQfDXGGoc9.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\YjytCh_DHd7.png.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\1reB yRWzmoSfbV.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\3h-yuTvu44f0svyy6wnc.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\8Ia5QiOlaiV.jpg.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\AWbwa.jpg.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\bw_hrUz.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\GayPngK B1HUHQ.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\GVkbNJkKs24Odzk VT.bmp.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\h1LwYy.png.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\hUqeQT7STFxLn4.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\iqqBK5 3zGlT.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\Itkt.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\M4SKd8Sw0aV5WX5X1.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\n0FbikD.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\QuXaGHNto5cRBrkUm9.bmp.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y 3lIDkOlrc\tYFkk5fUPnp7IHrB3g.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FnD9afpkw2UyTR-S.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Kn6jc8gaHXp9SW.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\g7LjIU75uO3kwGy.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\-2yB4ss4NgTWSGgQ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\cifr1qKdH_XG2.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\eMzZFs.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\GE-_UQaBbes.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\KKz5Opy32DS0plwb6.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\2j94iyK\E5z9RROlWPn\69fOetqgUPqvM\WlZ E1v.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\7FS6kYz\-gdblJaXzOJsKa.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\7FS6kYz\HXFHG_3fBp030Iii5BXt.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\7FS6kYz\Nm14mVHgw 8Ki.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\7FS6kYz\VyCLstj9Ktz9AEw9M.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\R8lAzSczDb6SOa_\c3D7SSPawbS_.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\R8lAzSczDb6SOa_\y0_dxEiSd.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\zKfjubAKar0bM\bBe6Ai.mp3.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\zKfjubAKar0bM\NfoKpMUtIT7XEj_oJ6nC\p5RFuipRP9H5Xsb9-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\zKfjubAKar0bM\RgXO-bxKsKIJSG\ECpH XKcPSPp9v3.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0RBtapF-dLB5gf8Rj.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\KqcP7M tzL cNzjajiW\-x1jPi.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\KqcP7M tzL cNzjajiW\p93P.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T-dBZv6nFX4UT2wXL\ErAW40wLRth3OKtd.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T-dBZv6nFX4UT2wXL\qTKrRpp9H.mkv.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T-dBZv6nFX4UT2wXL\9moMIRpQgI32oQHxXb0\SzJH9iqFPNVSmEgRxD.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T-dBZv6nFX4UT2wXL\9moMIRpQgI32oQHxXb0\bwOR8s rC4F1fZ\IV2-oMatS.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T-dBZv6nFX4UT2wXL\9moMIRpQgI32oQHxXb0\bwOR8s rC4F1fZ\LG94AazLEQ5p5QVz.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\2RN7S7 wQYQTY2dqI.mkv.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\p1icyxPo8j7Jz2kc6O.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\_DfWh.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\U6tafo25\4bB5ut4ZcY2.avi.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\U6tafo25\OHVvDRVxgILtnD7stl89.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vCEaXzlNZMQ\U6tafo25\z9errDpqkfip99N-m.mp4.reimageplus | Dropped File | Stream |
Unknown
|
...
|
»