Malicious
Classifications
Ransomware
Threat Names
-
Dynamic Analysis Report
Created on 2022-04-25T12:27:00
baba76d578be903c9d78e3d6417636ba6a8069cafe9ccccdfce2bc19b43fc299.exe
Windows Exe (x86-32)
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\baba76d578be903c9d78e3d6417636ba6a8069cafe9ccccdfce2bc19b43fc299.exe | Sample File | Binary |
malicious
|
...
|
»
File Reputation Information
»
Verdict |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4330bb |
Size Of Code | 0x31200 |
Size Of Initialized Data | 0x8600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-17 21:01:13+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x310c1 | 0x31200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.54 |
.rsrc | 0x434000 | 0x8385 | 0x8400 | 0x31400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.05 |
.reloc | 0x43e000 | 0xc | 0x200 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x402000 | 0x33099 | 0x31299 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
baba76d578be903c9d78e3d6417636ba6a8069cafe9ccccdfce2bc19b43fc299.exe | 1 | 0x00400000 | 0x0043FFFF | Relevant Image |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x04730000 | 0x04767FFF | Reflectively Loaded .NET Assembly |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\svhost.exe | Dropped File | Binary |
suspicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x439422 |
Size Of Code | 0x37600 |
Size Of Initialized Data | 0x4200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2015-10-08 01:13:18+00:00 |
Version Information (10)
»
CompanyName | Microsoft Corporation |
FileDescription | MSBuild.exe |
FileVersion | 4.6.1038.0 built by: NETFXREL2 |
InternalName | MSBuild.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | MSBuild.exe |
ProductName | Microsoft® .NET Framework |
ProductVersion | 4.6.1038.0 |
Comments | Flavor=Retail |
PrivateBuild | DDBLD597 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x37440 | 0x37600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.97 |
.rsrc | 0x43a000 | 0x3ef4 | 0x4000 | 0x37800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.27 |
.reloc | 0x43e000 | 0xc | 0x200 | 0x3b800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x402000 | 0x393f5 | 0x375f5 | 0x0 |
Digital Signature Information
»
Verification Status | Valid |
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2015-06-04 19:42 (UTC+2) |
Valid Until | 2016-09-04 19:42 (UTC+2) |
Algorithm | sha1_rsa |
Serial Number | 33 00 00 01 0A 2C 79 AE D7 79 7B A6 AC 00 01 00 00 01 0A |
Thumbprint | 3B DA 32 3E 55 2D B1 FD E5 F4 FB EE 75 D6 D5 B2 B1 87 EE DC |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2010-09-01 00:19 (UTC+2) |
Valid Until | 2020-09-01 00:29 (UTC+2) |
Algorithm | sha1_rsa |
Serial Number | 61 33 26 1A 00 00 00 00 00 31 |
Thumbprint | 3C AF 9B A2 DB 55 70 CA F7 69 42 FF 99 10 1B 99 38 88 E2 57 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 2 | 0x00400000 | 0x00439FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x042BE000 | 0x042BFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00199000 | 0x0019FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\RDhJ0CNFevzX\Desktop\2BCq2zisH1tDLrOOSW.csv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\438nbzlkP EaX9m.flv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\80TvEOvTr5nvyl.swf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8H3cx4bVP1NLZr8fhYb.swf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\A6CiMczxY2F3JXYRzK.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\A9li7.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\aA9p.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fch1HElCA7Cv3KXW.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\gPnVA1epmh.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\jKEImg2LCcB.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\kFzsu2uze8.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\lZ59hc.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\nI-Ynzgfo-bdwG.ods | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\qxMCjsWp9C.swf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\rfEzxhy.flv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\S byA0FI2i1A.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\UUZnNLpt1yyHK2REqD8.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\WUHo.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\Y9Yc7GFT5o-.flv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\Yc_dgQq9.swf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\_z9 qmOEfbbR2Ho.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\0b2BYJ.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\bCDo3xL3DQNnY-NDn8o.csv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\BP7Hlx-dC.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\HTPNUNi5N0PRF7q49.flv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\lohkShS91M7hT3L\- iPNtWwPnLb_xVEK.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\lohkShS91M7hT3L\a0LPQFabf2-tcp.flv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\lohkShS91M7hT3L\T3Pjk61xtk9Sizl9Gz7.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\8fuFu\lohkShS91M7hT3L\Wy9hdiHoa5p6DL6.wav | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\0tvBM_QdD3TVO2ZA_6P.ods | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\1gCPCj5iJQW.csv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\1yj7pDeYv0wl_14KUOPt.rtf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\22yziHM7PYbi2OW6R.pdf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\2qxTT.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\3wHRRlh-2tUJE8.doc | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\5BYO.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\6_8C7Suq3sh2Zdvr.ppt | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\7AVZTG3CoeJywumxSZt.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\998Wb55hD8qLh4.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\A0KaGTxVHzRgl2NU.ods | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Ai3doif_i6aorCOuoq.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\cJ6K_Ys9JTdNtND8.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\DkBw3ckGM uF2SMdXz.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\dXzsJ7_sQ.rtf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\FgTsNOb7Ndvo.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\fiE7zb85t8B-.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\FXtU7tJGkArCUt.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Gxt7.rtf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\h8t-RSY oy1WSABM.csv | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\hgaKU.odt | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\iriH.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\iSv2CXAx0sO0nwq3.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\LXAm.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\LXf5O1UnE8gZ7VPN-X.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Lxh6PbYU5lGk0.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\lyrRYp D-2Z.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\MSNffSwckP FbcIEuI5.doc | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\n7hKHIqS.rtf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\ocgatxC-6Ez0Hk_y.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\owF5pa QZMhBD.rtf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\p9uL--tRL_6UnNWprC.odt | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\pSJLpn8DrUrz1-Xy6Fw_.pdf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\q9j2C2vhqGqT8Y.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Qi06Dg7iSL hMONv94Db.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\QqWlqDBqRFVAm vqX4DG.pdf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\TDG1tR6SD8R 70ytf.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\uhTnuhWyZPoex.pdf | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\uIwqDmYW8Ql.docx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\vcYEH.doc | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\wlZTxESTUgU f3.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\WU7S.xls | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\wVE9flHzacBjM.pptx | Modified File | Audio |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\y8TckRi KxxqHv9oqq.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\ZJRfdPfcL.xlsx | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\ZWAFqo.pps | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\Outlook Files\achoo@gdllo.de.pst | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\0AkGZ7RwHa9JQW9htg8.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\1XcD0L9HgO vAf jK.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\6HEzLSBE7gYZeO.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\6xK8yFHYt9NwJGM.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\8YcKzqOL.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\b4zTcHI.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\BreSk RqWy7z.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\BRJpjfC.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\d-XNPCTgc1Q9.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gSIkAFh.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\gXgbf6roC6Lb.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\hlxInIph.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\I6Fm_t84SE.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\ivsui27SVr1Y3.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\lsOQhqoN27oebZQi8.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\mi45QG6WK.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\mJaL9VXieT_.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\NLit5D.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\prgQYDqfEtZPsUF.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\srPT.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\ssZyCkQ2_.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\sy8Zc6o0W2Dpzb.jpg | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\thhlqm_vXfrhAkJgqh4.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Tq-YO c2w6Tz7VNGz.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\Vmb OG1vu5V_PXk.png | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\ZfAtYXdgQ7TzJo4.bmp | Modified File | Stream |
clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Pictures\_LbBOR Qp.bmp | Modified File | Stream |
clean
|
...
|
»
b65a8f1dac0f41713ef3a4ab266b3c2eec7710713938fcd82ae1aa5c1c709098 | Embedded File | Image |
clean
|
...
|
»