242713ef...bd95 | VTI
Try VMRay Analyzer
VTI SCORE: 95/100
Dynamic Analysis Report
Classification: Dropper, Riskware, Downloader, Trojan, Ransomware

242713ef2f372f0d39ca8f01bd09c9f99bcfe850e156621c023dd9e0bfb9bd95 (SHA256)

CURRENT_DIRnwovkcyl.exe

Windows Exe (x86-32)

Created at 2018-10-03 03:03:00

Notifications (1/1)

Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.

Severity Category Operation Classification
4/5
File System Modifies content of user files Ransomware
  • Modifies the content of multiple user files. This is an indicator for an encryption attempt.
4/5
File System Renames user files Ransomware
  • Renames multiple user files. This is an indicator for an encryption attempt.
4/5
File System Known malicious file Trojan
3/5
Process Creates an unusally large number of processes -
3/5
Kernel Executes code with kernel privileges -
  • Executes code with kernel privileges to perform system level actions. This can sometimes be used to perform malicious actions and to avoid detection.
3/5
YARA YARA match -
  • Rule "VBA_Execution_Commands" from ruleset "Generic" has matched for "C:\Users\CIiHmnxMn6Ps\AppData\Roaming\MuA3C6WI.vbs"
  • Rule "VBA_Execution_Commands" from ruleset "Generic" has matched for "\Users\CIiHmnxMn6Ps\AppData\Roaming\MuA3C6WI.vbs"
2/5
Anti Analysis Resolves APIs dynamically to possibly evade static detection -
2/5
Device Sends control codes to connected devices -
1/5
Process Creates system object -
1/5
Process Creates process with hidden window -
  • The process ""C:\Windows\system32\cmd.exe" /C copy /V /Y "C:\Users\CIiHmnxMn6Ps\Desktop\CURRENT_DIRnwovkcyl.exe" "C:\Users\CIiHmnxMn6Ps\Desktop\NWYpDmnO.exe"" starts with hidden window.
  • The process ""C:\Windows\system32\cmd.exe" /C reg add "HKCU\Control Panel\Desktop" /v Wallpaper /t REG_SZ /d "C:\Users\CIiHmnxMn6Ps\AppData\Roaming\F7t5Hk0D.bmp" /f & reg add "HKCU\Control Panel\Desktop" /v WallpaperStyle /t REG_SZ /d "0" /f & reg add "HKCU\Control Panel\Desktop" /v TileWallpaper /t REG_SZ /d "0" /f" starts with hidden window.
  • The process ""C:\Windows\system32\cmd.exe" /C wscript //B //Nologo "C:\Users\CIiHmnxMn6Ps\AppData\Roaming\MuA3C6WI.vbs"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Microsoft Office 15\alfred.exe"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\en-US\jnwdui.dll.mui"" starts with hidden window.
  • The process "C:\Users\CIIHMN~1\AppData\Local\Temp\vIDhS3md64.exe" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\Templates\Genko_1.jtp"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\Workflow.Targets"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\Journal.exe"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\Templates\Seyes.jtp"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Mail\en-US\WinMail.exe.mui"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Portable Devices\restaurant.exe"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\MSBuild\expenditurevincenttablet.exe"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\en-US\MSPVWCTL.DLL.mui"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\Templates\Memo.jtp"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Mail\wabmig.exe"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Photo Viewer\en-US\ImagingDevices.exe.mui"" starts with hidden window.
  • The process ""C:\Users\CIiHmnxMn6Ps\Desktop\vRnqNMBW.bat" "C:\Program Files\Windows Journal\en-US\NBMapTIP.dll.mui"" starts with hidden window.
1/5
Network Performs DNS request -
1/5
Masquerade Changes folder appearance Riskware
1/5
File System Modifies application directory -
  • Modifies "c:\program files\java\jre1.8.0_131\bin\server\xusage.txt".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\accessibility.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\cmm\linear_rgb.pf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_ja.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\content-types.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\splash_11@2x-lic.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_sv.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_fr.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\splash@2x.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\ffjcext.zip".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidabrightitalic.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_es.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\splash.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\cldrdata.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_copynodrop32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_zh_cn.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\localedata.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_it.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\sunpkcs11.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\splash_11-lic.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_zh_hk.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\flavormap.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidatypewriterregular.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\javafx.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fontconfig.properties.src".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidabrightdemibold.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\invalid32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidatypewriterbold.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\sunjce_provider.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\cursors.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_movenodrop32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidabrightdemiitalic.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\bin\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\bin\server\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\psfontj2d.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\amd64\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\us_export_policy.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\cmm\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_copydrop32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidabrightregular.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidasansregular.ttf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_movedrop32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\java.policy".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_linkdrop32x32.gif".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management\snmp.acl.template".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management\jmxremote.access".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management\management.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\blacklisted.certs".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\blacklist".
  • Modifies "c:\program files\msbuild\microsoft\windows workflow foundation\v3.0\workflow.targets".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\chrome_200_percent.pak".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\psfont.properties.ja".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\local_policy.jar".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\chrome.dll.sig".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\extensions\external_extensions.json".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\external_extensions.json".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\chrome.exe.sig".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management-agent.jar".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\java.security".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\cacerts".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\da.pak".
  • Modifies "c:\program files\java\jre1.8.0_131\thirdpartylicensereadme-javafx.txt".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_pt_br.properties".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\sound.properties".
  • Modifies "c:\program files\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\access-bridge-64.jar".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\bn.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\chrome_100_percent.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\fil.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\installer\chrmstp.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\ext\sunmscapi.jar".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\extensions\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\installer\setup.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\drive.crx".
  • Modifies "c:\program files\microsoft office 15\clientx64\integratedoffice.exe".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\jfr\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\am.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\et.pak".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\kn.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\en-gb.pak".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\fonts\lucidasansdemibold.ttf".
  • Modifies "c:\program files\msbuild\microsoft\windows workflow foundation\v3.0\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\bg.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\id.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\icudtl.dat".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\installer\chrome.7z".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\images\cursors\win32_linknodrop32x32.gif".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\en-us.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\pt-br.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\he.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\el.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\nb.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\hi.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\gmail.crx".
  • Modifies "c:\program files\microsoft office 15\clientx64\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\lv.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\de.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\te.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ca.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\fr.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\gu.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ru.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ml.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ko.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\hu.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\sv.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\lt.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\snapshot_blob.bin".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\security\javaws.policy".
  • Modifies "c:\program files (x86)\google\chrome\application\setupmetrics\20170524140843.pma".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\fa.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\pt-pt.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\setupmetrics\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\sk.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ro.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\it.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ms.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\uk.pak".
  • Modifies "c:\program files\java\jre1.8.0_131\thirdpartylicensereadme.txt".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\th.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\sr.pak".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\features\webcompat@mozilla.org.xpi".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\tr.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\nl.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\logo.png".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_de.properties".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\smalllogocanary.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\smalllogo.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\docs.crx".
  • Modifies "c:\program files (x86)\mozilla firefox\crashreporter.exe".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\deploy\messages_zh_tw.properties".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\logocanary.png".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\visualelements\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\visualelements\visualelements_70.png".
  • Modifies "c:\program files (x86)\mozilla firefox\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\zh-tw.pak".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\visualelements\visualelements_150.png".
  • Modifies "c:\program files (x86)\mozilla firefox\minidump-analyzer.exe".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\features\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\nacl_irt_x86_64.nexe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\_platform_specific\win_x64\widevinecdmadapter.dll.sig".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\_platform_specific\win_x64\widevinecdm.dll.sig".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi".
  • Modifies "c:\program files (x86)\mozilla firefox\defaults\pref\channel-prefs.js".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\features\aushelper@mozilla.org.xpi".
  • Modifies "c:\program files (x86)\mozilla firefox\dependentlibs.list".
  • Modifies "c:\program files (x86)\mozilla firefox\maintenanceservice.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\es-419.pak".
  • Modifies "c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\chrome.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\hr.pak".
  • Modifies "c:\program files (x86)\mozilla firefox\uninstall\shortcuts_log.ini".
  • Modifies "c:\program files (x86)\mozilla firefox\maintenanceservice_installer.exe".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\features\e10srollout@mozilla.org.xpi".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\mr.pak".
  • Modifies "c:\program files (x86)\mozilla firefox\uninstall\helper.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\sl.pak".
  • Modifies "c:\program files (x86)\mozilla firefox\plugin-container.exe".
  • Modifies "c:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.0\workflow.visualbasic.targets".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\zh-cn.pak".
  • Modifies "c:\program files (x86)\mozilla maintenance service\updater.ini".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\manifest.json".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\crashreporter-override.ini".
  • Modifies "c:\program files (x86)\mozilla firefox\crashreporter.ini".
  • Modifies "c:\program files (x86)\google\chrome\application\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\gmp-clearkey\0.1\manifest.json".
  • Modifies "c:\program files (x86)\mozilla firefox\update-settings.ini".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\widevinecdm\_platform_specific\win_x64\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\extensions\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\visualelements\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\defaults\pref\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla firefox\uninstall\#readme_eman#.rtf".
  • Modifies "c:\program files (x86)\mozilla maintenance service\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\hijrah-config-umalqura.properties".
  • Modifies "c:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.0\#readme_eman#.rtf".
  • Modifies "c:\program files\java\jre1.8.0_131\lib\management\jmxremote.password.template".
  • Modifies "c:\program files (x86)\mozilla firefox\gmp-clearkey\0.1\#readme_eman#.rtf".
  • Modifies "c:\program files\microsoft office 15\clientx64\officeclicktorun.exe".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\58.0.3029.110.manifest".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\default_apps\youtube.crx".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\cs.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\fi.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ja.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\pl.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\locales\ta.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\resources.pak".
  • Modifies "c:\program files (x86)\google\chrome\application\master_preferences".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\features\firefox@getpocket.com.xpi".
  • Modifies "c:\program files (x86)\mozilla firefox\fonts\emojionemozilla.ttf".
  • Modifies "c:\program files (x86)\mozilla firefox\plugin-hang-ui.exe".
  • Modifies "c:\program files (x86)\mozilla firefox\wow_helper.exe".
  • Modifies "c:\program files (x86)\mozilla firefox\fonts\#readme_eman#.rtf".
1/5
File System Modifies operating system directory -
  • Creates file "C:\Windows\system32\Drivers\PROCEXP152.SYS" in the OS directory.
1/5
Persistence Installs system service -
1/5
File System Creates an unusually large number of files -
1/5
Network Connects to remote host -
1/5
Network Downloads data Downloader
  • URL "http://eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=START".
  • URL "http://eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=[ALL]460F9943EA70F103".
  • URL "http://eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=460F9943EA70F103|2891|1GB".
1/5
Network Connects to HTTP server -
  • URL "eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=START".
  • URL "eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=[ALL]460F9943EA70F103".
  • URL "eman.mygoodsday.org/addrecord.php?apikey=eman_api_key&compuser=LHNIWSJ|CIiHmnxMn6Ps&sid=19kSvLoQsaClDN7y&phase=460F9943EA70F103|2891|1GB".
1/5
PE Drops PE file Dropper
1/5
PE Executes dropped PE file -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image