ZeroCleare Wiper Malware | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification:
Dropper
Trojan
Pua
Threat Names:
RawDisk
Trojan.GenericKD.32949123
Trojan.Agent.EJCG
...

VMRay Threat Identifiers (15 rules, 21 matches)

SeverityCategoryOperationCountClassification
5/5
AntivirusMalicious content was detected by heuristic scan3-
5/5
ReputationKnown malicious file1Trojan
3/5
ExecutionExecutes code with kernel privileges1-
3/5
YARASuspicious content matched by YARA rules1-
2/5
ObfuscationResolves APIs dynamically to possibly evade static detection1-
2/5
Anti AnalysisTries to detect virtual machine1-
2/5
PersistenceInstalls kernel driver1-
2/5
Defense EvasionSends control codes to connected devices3-
2/5
Anti AnalysisCreates an unusually large number of processes1-
2/5
MasqueradeCreates a new process from a system binary1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Virtualization / Sandbox Evasion
Software Packing
Rootkit
Hidden Window
Credential Access
Discovery
Virtualization / Sandbox Evasion
Query Registry
Lateral Movement
Collection
Command and Control
Exfiltration
Impact

Sample Information

ID#423654
MD5
841ba553159d08ba6bee7435341a39e8
SHA1
bf60dd0f4f3069405365f6edc3766da9d0122bf8
SHA256
8133047094cf407e4b45efe4cf44f7b569e8c3133d1c598bba3188137401cc7c
FilenameClientUpdate.exe
File Size451.50 kB
Sample TypeWindows Exe (x86-64)

Analysis Information

Creation Time2020-01-17 20:01 (UTC+)
Analysis Duration00:02:00
Number of Monitored Processes101
Execution SuccessfulTrue
Reputation EnabledTrue
WHOIS EnabledFalse
Local AV EnabledTrue
Local AV Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
YARA EnabledTrue
YARA Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
Number of AV Matches5
Number of YARA Matches2
Termination ReasonTimeout
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image