VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Worm
|
Threat Names: |
Olympic Destroyer
Generic.Ransom.WCryG.751A6B2F
Mal/Generic-S
|
Host Process for Windows Services.exe
Windows Exe (x86-32)
Created at 2020-11-05T18:35:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Host Process for Windows Services.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x407d2e |
Size Of Code | 0x5e00 |
Size Of Initialized Data | 0xa00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-02 08:05:46+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.1 |
Comments | - |
CompanyName | Microsoft Corporation |
FileDescription | - |
FileVersion | 1.0.0.1 |
InternalName | Host Process for Windows Services.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | Host Process for Windows Services.exe |
ProductName | - |
ProductVersion | 1.0.0.1 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x5d34 | 0x5e00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.6 |
.rsrc | 0x408000 | 0x800 | 0x800 | 0x6000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.43 |
.reloc | 0x40a000 | 0xc | 0x200 | 0x6800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x7d00 | 0x5f00 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
host process for windows services.exe | 1 | 0x00E50000 | 0x00E5BFFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
host process for windows services.exe | 1 | 0x00E50000 | 0x00E5BFFF | Process Termination |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.WCryG.751A6B2F |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
OlympicDestroyer_Gen1 | Olympic Destroyer destructive malware | Worm |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_32.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_1024.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_sr.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrg~1\appdata\local\temp\armui.ini | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bWRd8dxM pn7NK2ZxYY.swf.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gkoi5oDLg3I.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LJw9T.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\r6_6ecjRu.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vCwIR.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\wysf8ApsC2_k.swf.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\CkzJcwF-T_AwbraA4MWA.avi.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\DCo-xn7gs6510.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\fcA9qJGasA7F1CNxnX.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\FQ4WV4Rq8zyb.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\fr0mD.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\FY4730gbBQhrVa J.avi.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\kMyC.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\NE-be6HdLUpf4N04.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\c_UY.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\DaO3.avi.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\DbuW7 AVRfVZ4Mwz.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\llL2AYEdzakX1Dxgfa.swf.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\6NJiby wnlgY.swf.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\dgJ1Cu86r I.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\f_OYDk.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\_EFlKKu1N1xc5dVxLO.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\8oN2827bxRQbgy N.flv.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\csWBpBz2NeS.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\ja hcjKSUJ6ece.mp4.sext | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\S2X8-FkEZzZP23.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\Tsn9NGG_VAkVfW_bv1g.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9ipY\HAE _NkXT9aKwYO\ETQ7i\VGiiaMPiZ\UT7DVa4lIuO.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j-pqgTUq9vExmNB4eXJ\-g3VNA.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j-pqgTUq9vExmNB4eXJ\9h7TCbmOvMAG.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j-pqgTUq9vExmNB4eXJ\Qd1 hcTvl.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j-pqgTUq9vExmNB4eXJ\UZPmC1-FYNK.mkv | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\explorerstartuplog_runonce.etl | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_idx.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_96.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_256.db | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrg~1\appdata\local\temp\adobearm.log | Modified File | Text |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\9435f817-fed2-454e-88cd-7f78fda62c48 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\system.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\application.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\security.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-kernel-whea%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-grouppolicy%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-offlinefiles%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-user profile service%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-terminalservices-localsessionmanager%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-branchcachesmb%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j-pqgTUq9vExmNB4eXJ\HELP_DECRYPT_YOUR_FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat | Dropped File | Stream |
Unknown
|
...
|
»