VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
csrhdp.exe
Windows Exe (x86-32)
Created at 2019-11-07T13:22:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\csrhdp.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-11-05 10:38 (UTC+1) |
Last Seen | 2019-11-07 13:40 (UTC+1) |
Names | Win32.Trojan.Delshad |
Families | Delshad |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x46a1d0 |
Size Of Code | 0x2b000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x3f000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-04 17:42:49+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x3f000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x440000 | 0x2b000 | 0x2a600 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
UPX2 | 0x46b000 | 0x1000 | 0x200 | 0x2aa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.15 |
Imports (7)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x46b0a0 | 0x6b0a0 | 0x2aaa0 | 0x0 |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptEncodeObject | 0x0 | 0x46b0a8 | 0x6b0a8 | 0x2aaa8 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BitBlt | 0x0 | 0x46b0b0 | 0x6b0b0 | 0x2aab0 | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x46b0b8 | 0x6b0b8 | 0x2aab8 | 0x0 |
ExitProcess | 0x0 | 0x46b0bc | 0x6b0bc | 0x2aabc | 0x0 |
GetProcAddress | 0x0 | 0x46b0c0 | 0x6b0c0 | 0x2aac0 | 0x0 |
VirtualProtect | 0x0 | 0x46b0c4 | 0x6b0c4 | 0x2aac4 | 0x0 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumW | 0x0 | 0x46b0cc | 0x6b0cc | 0x2aacc | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x46b0d4 | 0x6b0d4 | 0x2aad4 | 0x0 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetOpenW | 0x0 | 0x46b0dc | 0x6b0dc | 0x2aadc | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
csrhdp.exe | 1 | 0x00400000 | 0x0046BFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
csrhdp.exe | 1 | 0x00400000 | 0x0046BFFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.WCryG.4E19A59E |
Malicious
|
C:\\BOOTSECT.BAK.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BOOTSTAT.DAT.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BCD.LOG2.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BCD.LOG1.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\osetupui.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\TRY_TO_READ.html | Dropped File | Text |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPrWW2.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPrWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\PidGenX.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\OWOW32WW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\osetup.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ose.exe.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjPrrWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\OWOW32WW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\osetup.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\ose.exe.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»