VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Zusy.304957
|
oopsNO.ps1
PowerShell Script
Created at 2020-10-14T12:58:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "13 minutes" to "2 minutes, 10 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\EEBsYm5\AppData\Local\Temp\m1pgl9ij.0.cs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\m1pgl9ij.cmdline | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\m1pgl9ij.out | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\raurtmxx.0.cs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\raurtmxx.cmdline | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\raurtmxx.out | Dropped File | Text |
Unknown
|
...
|
»
c:\users\eebsym5\pictures\lzaa15lkh0wzl3 lfau\ly szqon188wz\1dmy5jnwmes_dsak\_-vchgnso5gojhdiyvkp.jpg.f0dbec | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\cvnsdvucz088htdbmjg\nilm\l6zmef0ht.m4a.f0dbec | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\th\F0DBEC-Readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\raurtmxx.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»