1da3bb21...15e3 | VTI
Try VMRay Analyzer
VTI SCORE: 96/100
Dynamic Analysis Report
Classification: Trojan

1da3bb217a3d771d357edfc401ac3835c29066e5d0a795e12aabd4b888bd15e3 (SHA256)

Godsomware.exe

Windows Exe (x86-32)

Created at 2018-10-06 16:50:00

Notifications (1/1)

The operating system was rebooted during the analysis.

Severity Category Operation Classification
4/5
OS Disables a crucial system tool -
4/5
File System Known malicious file Trojan
  • File "C:\Users\CIiHmnxMn6Ps\Desktop\Godsomware.exe" is a known malicious file.
2/5
Anti Analysis Makes direct system call to possibly evade hooking based sandboxes -
  • Makes a direct system call to "NtGdiSelectBitmap".
  • Makes a direct system call to "NtGdiGetDCObject".
  • Makes a direct system call to "NtGdiSaveDC".
  • Makes a direct system call to "NtGdiGetRandomRgn".
  • Makes a direct system call to "NtGdiExtSelectClipRgn".
  • Makes a direct system call to "NtGdiGetNearestColor".
  • Makes a direct system call to "NtGdiRestoreDC".
  • Makes a direct system call to "NtGdiBitBlt".
  • Makes a direct system call to "NtUserSelectPalette".
  • Makes a direct system call to "NtGdiDeleteObjectApp".
  • Makes a direct system call to "NtGdiCreateCompatibleDC".
  • Makes a direct system call to "NtGdiGetDCDword".
  • Makes a direct system call to "NtGdiCreateCompatibleBitmap".
  • Makes a direct system call to "NtGdiGetDIBitsInternal".
  • Makes a direct system call to "NtGdiExtGetObjectW".
1/5
Persistence Installs system startup script or application -
  • Adds "C:\Users\CIiHmnxMn6Ps\Desktop\Godsomware.exe" to Windows startup via registry.
1/5
Device Monitors mouse movements and clicks -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image