daea4b5ea119786d996f33895996396892fa0bdbb8f9e9fcc184a89d0d0cb85e (SHA256)
Defender.exe
Created at 2018-02-08 14:58:00
Notifications (1/1)
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
5/5
|
File System | Encrypts content of user files | Ransomware | |
|
||||
3/5
|
Browser | Reads data related to browser cookies | - | |
|
||||
3/5
|
Browser | Reads data related to saved browser credentials | - | |
|
||||
|
||||
2/5
|
Browser | Reads data related to browsing history | - | |
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
|
||||
1/5
|
Network | Performs DNS request | - | |
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
1/5
|
File System | Modifies operating system directory | - | |
|
||||
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
1/5
|
Network | Downloads data | Downloader | |
|
||||
1/5
|
Network | Connects to HTTP server | - | |
|
||||
1/5
|
PE | Drops PE file | Dropper | |
|
||||
1/5
|
PE | Executes dropped PE file | - | |
|