VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Wiper, Trojan |
dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe
Windows Exe (x86-32)
Created at 2019-05-15T23:24:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2018-11-03 13:50 (UTC+1) |
Last Seen | 2019-03-30 07:49 (UTC+1) |
Names | Win32.Trojan.Cryfile |
Families | Cryfile |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x46d600 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x44000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1992-06-19 22:22:17+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x44000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x445000 | 0x29000 | 0x28800 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.92 |
.rsrc | 0x46e000 | 0x1000 | 0xa00 | 0x28c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.21 |
Imports (8)
»
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x46e82c | 0x6e82c | 0x2942c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Add | 0x0 | 0x46e834 | 0x6e834 | 0x29434 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SaveDC | 0x0 | 0x46e83c | 0x6e83c | 0x2943c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x46e844 | 0x6e844 | 0x29444 | 0x0 |
ExitProcess | 0x0 | 0x46e848 | 0x6e848 | 0x29448 | 0x0 |
GetProcAddress | 0x0 | 0x46e84c | 0x6e84c | 0x2944c | 0x0 |
VirtualProtect | 0x0 | 0x46e850 | 0x6e850 | 0x29450 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantCopy | 0x0 | 0x46e858 | 0x6e858 | 0x29458 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathA | 0x0 | 0x46e860 | 0x6e860 | 0x29460 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x46e868 | 0x6e868 | 0x29468 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueA | 0x0 | 0x46e870 | 0x6e870 | 0x29470 | 0x0 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed | - | 32-bit | 0x0046D600 |
![]() |
![]() |
...
|
dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe | 1 | 0x00400000 | 0x0046EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00680000 | 0x00680FFF | First Execution | - | 32-bit | 0x00680FEF |
![]() |
![]() |
...
|
dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe | 1 | 0x00400000 | 0x0046EFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31335298 |
Malicious
|
C:\Users\FD1HVy\Desktop\6Ap4.png.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\73OqHhCstnZXqrw.m4a.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dnasmalwareprovider!dailyransomwaresbd5d3ebe6150f53c1535e1667a18bbd4831751a414e7518dc8e1d15a19db95b3.exe.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Fcr1f3Gzw_W.avi.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\FQqQPCoYEB.jpg.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GMOyXDXwFM8W7-LhS.swf.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\gv-rKvbphTHL.odp.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IHFgpxkCmC_zEG.wav.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\J5-kjHCPXByZQnhDJn.mp3.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kbF_2PW7TjoQ4IMqkI.bmp.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kvxI68o_1uIf1.avi.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\nbWphIhGB6Uy0.flv.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oFb2U6s9m6U6gOPb.mkv.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OKWfLhmwWcu5qOaGL.avi.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rrB-W8Ex2Gbzq310V5Y.jpg.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Sa rHH25WBZ3QNDj7vy.jpg.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WZcxh9yKmkx2N8.m4a.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\FQH0eS7fuhi.flv.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\SS1V.mp3.FilGZmsp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0Dq8DV.jpg.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\0X-S5DVXJ55.ppt.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\2IpG0.wav.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\41jdCZmpo.m4a.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\6oa-CSF.pptx.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Ag_S2MWic2.png.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\aLLtQe.avi.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\AURvHfheOx1i.swf.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\BqgUDiIk osrwPL.mp3.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\desktop.ini.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Jl2N2rnE59pjXp.xls.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\JZuk.bmp.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Lcy6ULqCFh5oc.m4a.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\LPTP-K_YKmqLf5vm.xlsx.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\rwhEj_au.m4a.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\v7ySBIDKOsB6.wav.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\vAirtIzQaFanKF.swf.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\8JhfB.jpg.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\9Q5R_fBUKWX9lHvs25T.bmp.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\AMM2g-fJbZQfHhiIiTsQ.docx.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\F n0c9A.mkv.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\Iv_UL1Smn68W.pptx.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\LdiI7dOGdPlqqn4FPm.csv.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\p5KNKVfrENUFkNTd.jpg.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\y8Oq3F1\x8c4k zgybMBqz.pps.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ynYByG93A60UMcX.gif.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ZsRJeI7s.mkv.FilGZmsp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\\!!ÊàêÐàñøèôðîâàòüÝòóÏàðàøó.txt | Dropped File | Text |
Not Queried
|
...
|
»