47f5a231...09b4 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 94/100
Dynamic Analysis Report
Classification: Trojan, Dropper, Ransomware

47f5a231f7cd0e36508ca6ff8c21c08a7248f0f2bd79c1e772b73443597b09b4 (SHA256)

CUsersSonyAppDataLocalTemphvwfcsky8521.exe

Windows Exe (x86-32)

Created at 2019-02-09 12:20:00

Notifications (2/2)

Every analysis has a preconfigured maximum VM disk size for temporary changes. This limit was reached during this analysis and, as an result, the analysis was terminated prematurely.

The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.

Top Threat Indicators (View all 16 threat indicators)

Screenshots

Monitored Processes

Analysis Information

Creation Time 2019-02-09 13:20 (UTC+1)
Analysis Duration 00:03:44
Number of Monitored Processes 1497
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
YARA Enabled True
Termination Reason VM disk exhausted
Tags

Sample Information

ID #445341
MD5 faf4de4e1c5d8e4241088c90cfe8eddd Copy to Clipboard
SHA1 fcd241fdcd462199f2907ca34c73ce9c89b03e5f Copy to Clipboard
SHA256 47f5a231f7cd0e36508ca6ff8c21c08a7248f0f2bd79c1e772b73443597b09b4 Copy to Clipboard
SSDeep 24576:2d2D4s/zj4pvOmB5h8DlVeZUEJt90nPx103CdnOQOdmdbDJKo:jDHzk1jZUElqg3bQOdmdbDJKo Copy to Clipboard
ImpHash 27f610a2966ffaa9958098af7bf71994 Copy to Clipboard
Filename CUsersSonyAppDataLocalTemphvwfcsky8521.exe
File Size 1.22 MB
File Type Windows Exe (x86-32)

Analyzer Information

Dynamic Analyzer Build Date 2019-01-08 16:19 (UTC+1)
Dynamic Analyzer Version 2.3.2
Static Analyzer Version 1.0.1
VTI Ruleset Version 3.1
YARA Built-in Ruleset Version 1.1
Analysis Report Layout Version 3
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image