http://financialbroker.gq
Created at 2018-04-24 10:30:00
Notifications (2/3)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
5/5
|
Anti Analysis | Tries to detect virtual machine | - | |
|
||||
5/5
|
File System | Modifies application directory | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
5/5
|
OS | Modifies certificate store | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
5/5
|
Information Stealing | Reads certificate data | - | |
|
||||
|
||||
5/5
|
File System | Creates an unusually large number of files | - | |
|
||||
5/5
|
File System | Encrypts content of user files | Ransomware | |
|
||||
5/5
|
Injection | Writes into the memory of another running process | - | |
|
||||
4/5
|
Process | Creates process | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
4/5
|
Process | Reads from memory of another process | - | |
|
||||
4/5
|
Network | Downloads data | Downloader | |
|
||||
|
||||
|
||||
|
||||
2/5
|
Network | Associated with known malicious/suspicious URLs | - | |
|
||||
|
||||
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
1/5
|
Process | Overwrites code | - | |
|
||||
1/5
|
Network | Connects to HTTP server | - | |
|
||||
|
||||
|
||||
|