VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Trojan.GenericKD.32812536
Mal/Generic-S
|
vbcudt.exe
Windows Exe (x86-64)
Created at 2020-02-06T10:30:00
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vbcudt.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x73f680 |
Size Of Code | 0x133000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x20c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x20c000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x60d000 | 0x133000 | 0x132a00 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.87 |
UPX2 | 0x740000 | 0x1000 | 0x200 | 0x132c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.63 |
Imports (3)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x740050 | 0x340050 | 0x132c50 | 0x0 |
GetProcAddress | 0x0 | 0x740058 | 0x340058 | 0x132c58 | 0x0 |
VirtualProtect | 0x0 | 0x740060 | 0x340060 | 0x132c60 | 0x0 |
VirtualAlloc | 0x0 | 0x740068 | 0x340068 | 0x132c68 | 0x0 |
VirtualFree | 0x0 | 0x740070 | 0x340070 | 0x132c70 | 0x0 |
ExitProcess | 0x0 | 0x740078 | 0x340078 | 0x132c78 | 0x0 |
winmm.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeEndPeriod | 0x0 | 0x740088 | 0x340088 | 0x132c88 | 0x0 |
ws2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAGetOverlappedResult | 0x0 | 0x740098 | 0x340098 | 0x132c98 | 0x0 |
Memory Dumps (31)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | First Execution |
![]() |
64-bit | 0x0073F680 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00439530 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0042E8B0 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00403B80 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00455D20 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004139F0 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00401070 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0043A500 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00402070 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0042B000 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00454517 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0043A700 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0041BF50 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004139F0 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00488020 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00410C80 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004A57C0 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00440010 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004A7000 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004A82E1 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004AB9F0 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004C9A30 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00503860 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0054C770 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x004BFF10 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0054B880 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0048C04D |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00566E20 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0043E11D |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x00450D30 |
![]() |
![]() |
...
|
vbcudt.exe | 1 | 0x00400000 | 0x00740FFF | Content Changed |
![]() |
64-bit | 0x0042ABD0 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32812536 |
Malicious
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\sv-SE\DECRYPT_EGMWV_FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.egmwv | Dropped File | Stream |
Unknown
|
...
|
»