VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Worm
|
Threat Names: |
WannaCry
Generic.Ransom.Loli.803D727B
Generic.Ransom.Loli.A9CD12DA
|
software-launcher.exe
Windows Exe (x86-32)
Created at 2020-09-02T11:14:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\software-launcher.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x424b66 |
Size Of Code | 0x22c00 |
Size Of Initialized Data | 0x11000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-01 15:47:05+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | Microsoft Corporation |
FileDescription | System |
FileVersion | 1.0.0.0 |
InternalName | software-launcher.exe |
LegalCopyright | Copyright © Microsoft Corporation 2020 |
LegalTrademarks | - |
OriginalFilename | software-launcher.exe |
ProductName | System |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x22b74 | 0x22c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.84 |
.rsrc | 0x426000 | 0x10cb0 | 0x10e00 | 0x22e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.91 |
.reloc | 0x438000 | 0xc | 0x200 | 0x33c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x24b3c | 0x22d3c | 0x0 |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
software-launcher.exe | 1 | 0x000B0000 | 0x000E9FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x008A1000 | 0x008A1FFF | First Execution |
![]() |
32-bit | 0x008A1000 |
![]() |
![]() |
...
|
buffer | 1 | 0x008A1000 | 0x008A1FFF | Content Changed |
![]() |
32-bit | 0x008A1D87 |
![]() |
![]() |
...
|
buffer | 1 | 0x008A1000 | 0x008A1FFF | Content Changed |
![]() |
32-bit | 0x008A1F74 |
![]() |
![]() |
...
|
buffer | 1 | 0x008A2000 | 0x008A2FFF | First Execution |
![]() |
32-bit | 0x008A2000 |
![]() |
![]() |
...
|
buffer | 1 | 0x008A2000 | 0x008A2FFF | Content Changed |
![]() |
32-bit | 0x008A21B0 |
![]() |
![]() |
...
|
buffer | 1 | 0x0082B000 | 0x0082BFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04931000 | 0x04932FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04933000 | 0x04934FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04A80000 | 0x04A83FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
software-launcher.exe | 1 | 0x000B0000 | 0x000E9FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Loli.803D727B |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
ransomware_windows_wannacry | WannaCry / WannaCryptor ransomware | Worm, Ransomware |
5/5
|
...
|
C:\Users\FD1HVy\Desktop\0AnA0vZk.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\1t8mDR.jpg.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7wdYXjKcwK4g32pSz.pptx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ARRXev3Mman5ZXl_hU.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DfKt340.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\F2Zph36bGvFL1Y8.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\FQAxEs.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GJ 5nBR8.jpg.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\h 8YJOiiEqZdgeYjPirv.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hizAwUh2j6satr-.avi.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ITjYho8KshiaXF3s6dL.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IutzQs5O.mp4.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\izYGAmbLee1.mp4.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\j0g1E J1dJ6jpYrw2.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\nerINvzvqPpVy5jmdDIF.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\P7a19TlEPOBemPq3t.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pBpvOyev.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\RJyw0fBQM2YxvBD_Jfl.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\-rgJK8d18aGGKjf3jJS6.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0ipeRQ95P5vPU.pptx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AKqc47LFj_gG.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CW2G Cl.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\JzyiGvQ.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\kTNR_WpOK.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\lOc6s5LmDI.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\lRZjIYnQnY19.pptx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\NmJxA2sBDwyT.docx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\o3iRBVFr.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\oTRPcpyo7xlnr8xSoB.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\rDY-p.docx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\s9Q9MbsobyPmk.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\S9td1yxQaW.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\tYx7dofd2TiCHl.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\u dyL-47D6N2ohhiX8v.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WuUKAB.docx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\YfVXE.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_Lz08ftp5sW.pptx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\HYVYAe7mdnOqw.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\RpZM0W8PY7CeeXD.pptx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\umP4YYQ84x7G.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\VqL UPl-9nlySS.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\WI5sqFLMbDy3IJuvREh2.rtf.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Hk-3y4 Z\x H8Jy Bf7dELLms9.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\ih77vT8qXDGJqo.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\_kNwQIeg4R.xlsx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\0eFKcOxh Sm8 S9YH4xl.doc.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\ee6WGRBk.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\Gk8AwiM1m5AaQm_T.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\kddRGMgOJ8N0RrGo.csv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\LIOj1kQn.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\LxNUTk3Hkq.docx.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\CKfW0B\whiTQc-OuZensEQ12.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\Eg1_.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\fOYUV97.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\jSfdGzcY5.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\KX fS3.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\orp-H_0BxF_vJR.odt.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jIb9\cKJStRzg4T\vSK6QtK2.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7B0kkOI DGv.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\9ul6s6.bmp.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\c7mA.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\EP1eh.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Hp19aFBT3HJ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\jERmwWHTZRt4pIGGnS.bmp.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Jw_i71pDYLFF.bmp.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\K9HC5.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NX2OX6naJX1GO-.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\u1amgRx.jpg.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\VVGX9cId3Ta8aM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wBbfZbe6Y3S3j.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\YBR1tSh.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZDpNUoM.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\1oQx2PlaY_9.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\9nPz82rQ.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\BgEHQ.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\QQoT8tuRcptR.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\tsjb.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\wh 5WIYWVVePs.bmp.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oZXDrM3YMlGZ8Vdp\xmm4L4s2nF.png.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S6eyKYGkszOpo_Wns.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\zPvf.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\8xhRDpIXkQ\Ay82dnBnZ0.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\I6ukkqQO3s-oI\B-m8zgB-tN.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\I6ukkqQO3s-oI\IePDQOLDlXqx16NB.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\OTtzwEjTf44G4cOL-.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\v6izgGjRNal8r.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\_0yROMHaywmWB62\JtAM-IeI5zVHJ8JcaEy.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\_0yROMHaywmWB62\kieyJ5AS1a\C6yoIpfEMh8.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\_0yROMHaywmWB62\pezVtXsxWzeTU\J4zixoRAM85ZU_.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\_0yROMHaywmWB62\pezVtXsxWzeTU\TvkUIQZ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WLmCv\_0yROMHaywmWB62\pezVtXsxWzeTU\xvWtvx6.mp3.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ekjH7sDmNVPwRikoTN.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\JPUUgAznNxhcK48TDUa.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\kDGc-Xgc2shNr4vrZT.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\sB-YTh6ciDeYAp8ZBPh_.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Wx_Kv3R.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\muAGeWhYavWHMk.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\xf2O1N.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\xnvSTS8K1jN.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\27Pk-PuvZPM\VrUFB4O9EszBqKfX0FY.mp4.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\27Pk-PuvZPM\QL0ZT2e_Y7ozGq8\0hn-IH6hyLLR2eWJ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\27Pk-PuvZPM\QL0ZT2e_Y7ozGq8\EwAZIL02ki.avi.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\27Pk-PuvZPM\QL0ZT2e_Y7ozGq8\ga-cc9eyoSy5YnCDWD6.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\27Pk-PuvZPM\QL0ZT2e_Y7ozGq8\x22Q.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\7nq1ciG2EUE.avi.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\NN07eaIQk.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\EzLrLSlA1TZf8Z\9-vMHkBEUJb5v.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\EzLrLSlA1TZf8Z\aikBLF6BI26sgMMD.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\EzLrLSlA1TZf8Z\vRSX.avi.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\EzLrLSlA1TZf8Z\1KHIKa\TJx yA_2Rxpi.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\EzLrLSlA1TZf8Z\1KHIKa\xjvDAivargd99qJKD.mkv.klavins | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSFmOD gwJSu xU3b\j-dNPr5d3JjQc75LvL\xFxdc\enTGQchT.avi.klavins | Dropped File | Stream |
Unknown
|
...
|
»