VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Trojan, Dropper, Ransomware |
c65df5ec5152af018ff362039351255ba7b59ea844639619f73d96ea135ab1f0 (SHA256)
CUsersGrujaAppDataRoaming6Xx3WI1ICfwJbN6F1OD~1.EXE
Windows Exe (x86-32)
Created at 2019-01-18 08:45:00
Notifications (2/2)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Kernel Graph 1

Code Block #1 (EP #1)
»
Information | Value |
---|---|
Trigger | KiRetireDpcList+0x1b5 |
Start Address | 0xfffffa800193a950 |
Execution Path #1 (length: 1, count: 2, processes: 1)
»
Information | Value |
---|---|
Sequence Length | 1 |
Processes
»
Process | Count |
---|---|
Process 32 (System, PID: 4) | 2 |
Sequence
»
Symbol | Parameters |
---|---|
ExQueueWorkItem | WorkItem_ptr = 0xfffffa80019a648b, WorkItem_deref_List.Flink_unk = 0x0, WorkItem_deref_List.Blink_unk = 0x0, WorkItem_deref_WorkerRoutine_unk = 0xfffffa80019ab070, WorkItem_deref_Parameter_ptr = 0xfffffa80019a624b, QueueType_unk = 0x1, WorkItem_ptr_out = 0xfffffa80019a648b, WorkItem_deref_List.Flink_unk_out = 0x0, WorkItem_deref_List.Blink_unk_out = 0x0, WorkItem_deref_WorkerRoutine_unk_out = 0xfffffa80019ab070, WorkItem_deref_Parameter_ptr_out = 0xfffffa80019a624b |
Code Block #2 (EP #2)
»
Information | Value |
---|---|
Trigger | ExpWorkerThread+0x10f |
Start Address | 0xfffffa80019ab070 |
Execution Path #2 (length: 1, count: 1, processes: 1 incomplete)
»
Information | Value |
---|---|
Sequence Length | 1 |
Processes
»
Process | Count |
---|---|
Process 32 (System, PID: 4) | 1 |
Sequence
»
Symbol | Parameters |
---|---|
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x1ccb5, Tag = 0x784d6452, ret_val_ptr_out = 0xfffffa80019fa000 |
Kernel Graph 2

Code Block #3 (EP #3)
»
Information | Value |
---|---|
Trigger | ExpWorkerThread+0x10f |
Start Address | 0xfffffa8001970e80 |
Execution Path #3 (length: 2, count: 1, processes: 1 incomplete)
»
Information | Value |
---|---|
Sequence Length | 2 |
Processes
»
Process | Count |
---|---|
Process 32 (System, PID: 4) | 1 |
Sequence
»
Symbol | Parameters |
---|---|
ExAllocatePoolWithTag | PoolType_unk = 0x0, NumberOfBytes_ptr = 0x1d2ab, Tag = 0x616d6443, ret_val_ptr_out = 0xfffffa8001a17000 |
KeSetTimer | Timer_unk = 0xfffffa800194fa28, DueTime_unk = 0xffffffffb5a0c861, Dpc_unk = 0xfffffa800194fa68, Timer_unk_out = 0xfffffa800194fa28, ret_val_out = 0 |