3012f472969327d5f8c9dac63b8ea9c5cb0de002d16c120a6bba4685120f58b4 (SHA256)
eqBNr.exe
Created at 2018-11-27 19:48:00
Notifications (2/3)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
4/5
|
File System | Modifies content of user files | Ransomware | |
|
||||
4/5
|
File System | Known malicious file | Trojan | |
|
||||
4/5
|
Injection | Writes into the memory of another running process | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
4/5
|
Injection | Modifies control flow of another process | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
3/5
|
OS | Modifies certificate store | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
3/5
|
Browser | Reads data related to browser cookies | - | |
|
||||
|
||||
3/5
|
Persistence | Adds file to open the next time Excel is launched | - | |
|
||||
3/5
|
Persistence | Adds file to open the next time Word is launched | - | |
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
|
||||
1/5
|
Process | Creates a page with write and execute permissions | - | |
|
||||
1/5
|
Anti Analysis | Resolves APIs dynamically | - | |
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
1/5
|
OS | Uses encryption API | - | |
|