VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Generic.Ransom.MedusaLocker.942644D7
Generic.Ransom.MedusaLocker.3F6297C8
Generic.Ransom.MedusaLocker.1F954364
|
OP_new.exe
Windows Exe (x86-32)
Created at 2020-05-30T06:25:00
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x43aea8 |
Size Of Code | 0x73400 |
Size Of Initialized Data | 0x37600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-20 16:30:29+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x732a6 | 0x73400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.53 |
.rdata | 0x475000 | 0x2c8ca | 0x2ca00 | 0x73800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.62 |
.data | 0x4a2000 | 0x4a68 | 0x3800 | 0xa0200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.85 |
.rsrc | 0x4a7000 | 0x1e0 | 0x200 | 0xa3a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x4a8000 | 0x5ce4 | 0x5e00 | 0xa3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.59 |
Imports (11)
»
KERNEL32.dll (137)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Process32NextW | 0x0 | 0x475078 | 0xa0818 | 0x9f018 | 0x427 |
Process32FirstW | 0x0 | 0x47507c | 0xa081c | 0x9f01c | 0x425 |
CreateProcessW | 0x0 | 0x475080 | 0xa0820 | 0x9f020 | 0xe4 |
GetTickCount | 0x0 | 0x475084 | 0xa0824 | 0x9f024 | 0x303 |
CopyFileW | 0x0 | 0x475088 | 0xa0828 | 0x9f028 | 0xac |
GetCurrentProcess | 0x0 | 0x47508c | 0xa082c | 0x9f02c | 0x215 |
WriteConsoleW | 0x0 | 0x475090 | 0xa0830 | 0x9f030 | 0x609 |
CreateToolhelp32Snapshot | 0x0 | 0x475094 | 0xa0834 | 0x9f034 | 0xfa |
OpenProcess | 0x0 | 0x475098 | 0xa0838 | 0x9f038 | 0x406 |
WaitForSingleObject | 0x0 | 0x47509c | 0xa083c | 0x9f03c | 0x5cf |
TerminateProcess | 0x0 | 0x4750a0 | 0xa0840 | 0x9f040 | 0x584 |
FindClose | 0x0 | 0x4750a4 | 0xa0844 | 0x9f044 | 0x173 |
FindNextVolumeW | 0x0 | 0x4750a8 | 0xa0848 | 0x9f048 | 0x18f |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x4750ac | 0xa084c | 0x9f04c | 0x320 |
FindVolumeClose | 0x0 | 0x4750b0 | 0xa0850 | 0x9f050 | 0x196 |
SetVolumeMountPointW | 0x0 | 0x4750b4 | 0xa0854 | 0x9f054 | 0x56c |
FindFirstVolumeW | 0x0 | 0x4750b8 | 0xa0858 | 0x9f058 | 0x184 |
QueryDosDeviceW | 0x0 | 0x4750bc | 0xa085c | 0x9f05c | 0x43e |
GetEnvironmentVariableW | 0x0 | 0x4750c0 | 0xa0860 | 0x9f060 | 0x235 |
GetLogicalDrives | 0x0 | 0x4750c4 | 0xa0864 | 0x9f064 | 0x264 |
GetProcessHeap | 0x0 | 0x4750c8 | 0xa0868 | 0x9f068 | 0x2b0 |
MoveFileExW | 0x0 | 0x4750cc | 0xa086c | 0x9f06c | 0x3e1 |
SetFilePointerEx | 0x0 | 0x4750d0 | 0xa0870 | 0x9f070 | 0x51b |
HeapAlloc | 0x0 | 0x4750d4 | 0xa0874 | 0x9f074 | 0x341 |
CloseHandle | 0x0 | 0x4750d8 | 0xa0878 | 0x9f078 | 0x86 |
GetLastError | 0x0 | 0x4750dc | 0xa087c | 0x9f07c | 0x25d |
SetFileAttributesW | 0x0 | 0x4750e0 | 0xa0880 | 0x9f080 | 0x515 |
GetFileAttributesW | 0x0 | 0x4750e4 | 0xa0884 | 0x9f084 | 0x241 |
CreateFileW | 0x0 | 0x4750e8 | 0xa0888 | 0x9f088 | 0xca |
WriteFile | 0x0 | 0x4750ec | 0xa088c | 0x9f08c | 0x60a |
HeapSize | 0x0 | 0x4750f0 | 0xa0890 | 0x9f090 | 0x34a |
GetConsoleMode | 0x0 | 0x4750f4 | 0xa0894 | 0x9f094 | 0x1fa |
GetConsoleCP | 0x0 | 0x4750f8 | 0xa0898 | 0x9f098 | 0x1e8 |
FlushFileBuffers | 0x0 | 0x4750fc | 0xa089c | 0x9f09c | 0x19d |
SetStdHandle | 0x0 | 0x475100 | 0xa08a0 | 0x9f0a0 | 0x542 |
FreeEnvironmentStringsW | 0x0 | 0x475104 | 0xa08a4 | 0x9f0a4 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x475108 | 0xa08a8 | 0x9f0a8 | 0x233 |
GetCommandLineW | 0x0 | 0x47510c | 0xa08ac | 0x9f0ac | 0x1d5 |
GetCommandLineA | 0x0 | 0x475110 | 0xa08b0 | 0x9f0b0 | 0x1d4 |
GetOEMCP | 0x0 | 0x475114 | 0xa08b4 | 0x9f0b4 | 0x293 |
GetACP | 0x0 | 0x475118 | 0xa08b8 | 0x9f0b8 | 0x1b0 |
IsValidCodePage | 0x0 | 0x47511c | 0xa08bc | 0x9f0bc | 0x386 |
GetFileType | 0x0 | 0x475120 | 0xa08c0 | 0x9f0c0 | 0x24a |
HeapReAlloc | 0x0 | 0x475124 | 0xa08c4 | 0x9f0c4 | 0x348 |
GetTimeZoneInformation | 0x0 | 0x475128 | 0xa08c8 | 0x9f0c8 | 0x30a |
EnumSystemLocalesW | 0x0 | 0x47512c | 0xa08cc | 0x9f0cc | 0x152 |
GetUserDefaultLCID | 0x0 | 0x475130 | 0xa08d0 | 0x9f0d0 | 0x30e |
HeapFree | 0x0 | 0x475134 | 0xa08d4 | 0x9f0d4 | 0x345 |
GetFileSizeEx | 0x0 | 0x475138 | 0xa08d8 | 0x9f0d8 | 0x248 |
IsValidLocale | 0x0 | 0x47513c | 0xa08dc | 0x9f0dc | 0x388 |
GetTimeFormatW | 0x0 | 0x475140 | 0xa08e0 | 0x9f0e0 | 0x308 |
GetDateFormatW | 0x0 | 0x475144 | 0xa08e4 | 0x9f0e4 | 0x21f |
GetStdHandle | 0x0 | 0x475148 | 0xa08e8 | 0x9f0e8 | 0x2ce |
ReadFile | 0x0 | 0x47514c | 0xa08ec | 0x9f0ec | 0x46c |
OpenMutexW | 0x0 | 0x475150 | 0xa08f0 | 0x9f0f0 | 0x402 |
Sleep | 0x0 | 0x475154 | 0xa08f4 | 0x9f0f4 | 0x575 |
CreateMutexW | 0x0 | 0x475158 | 0xa08f8 | 0x9f0f8 | 0xd9 |
GetModuleFileNameW | 0x0 | 0x47515c | 0xa08fc | 0x9f0fc | 0x270 |
SetEnvironmentVariableW | 0x0 | 0x475160 | 0xa0900 | 0x9f100 | 0x50c |
EncodePointer | 0x0 | 0x475164 | 0xa0904 | 0x9f104 | 0x12b |
DecodePointer | 0x0 | 0x475168 | 0xa0908 | 0x9f108 | 0x107 |
RaiseException | 0x0 | 0x47516c | 0xa090c | 0x9f10c | 0x45b |
GetCurrentThreadId | 0x0 | 0x475170 | 0xa0910 | 0x9f110 | 0x21a |
IsProcessorFeaturePresent | 0x0 | 0x475174 | 0xa0914 | 0x9f114 | 0x381 |
QueueUserWorkItem | 0x0 | 0x475178 | 0xa0918 | 0x9f118 | 0x450 |
GetModuleHandleExW | 0x0 | 0x47517c | 0xa091c | 0x9f11c | 0x273 |
EnterCriticalSection | 0x0 | 0x475180 | 0xa0920 | 0x9f120 | 0x12f |
LeaveCriticalSection | 0x0 | 0x475184 | 0xa0924 | 0x9f124 | 0x3b8 |
TryEnterCriticalSection | 0x0 | 0x475188 | 0xa0928 | 0x9f128 | 0x59f |
DeleteCriticalSection | 0x0 | 0x47518c | 0xa092c | 0x9f12c | 0x10e |
FormatMessageW | 0x0 | 0x475190 | 0xa0930 | 0x9f130 | 0x1a5 |
WideCharToMultiByte | 0x0 | 0x475194 | 0xa0934 | 0x9f134 | 0x5f6 |
QueryPerformanceCounter | 0x0 | 0x475198 | 0xa0938 | 0x9f138 | 0x446 |
MultiByteToWideChar | 0x0 | 0x47519c | 0xa093c | 0x9f13c | 0x3e8 |
FindFirstFileExW | 0x0 | 0x4751a0 | 0xa0940 | 0x9f140 | 0x179 |
FindNextFileW | 0x0 | 0x4751a4 | 0xa0944 | 0x9f144 | 0x18a |
GetFileAttributesExW | 0x0 | 0x4751a8 | 0xa0948 | 0x9f148 | 0x23e |
SetLastError | 0x0 | 0x4751ac | 0xa094c | 0x9f14c | 0x52a |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4751b0 | 0xa0950 | 0x9f150 | 0x35a |
CreateEventW | 0x0 | 0x4751b4 | 0xa0954 | 0x9f154 | 0xbe |
SwitchToThread | 0x0 | 0x4751b8 | 0xa0958 | 0x9f158 | 0x57f |
TlsAlloc | 0x0 | 0x4751bc | 0xa095c | 0x9f15c | 0x596 |
TlsGetValue | 0x0 | 0x4751c0 | 0xa0960 | 0x9f160 | 0x598 |
TlsSetValue | 0x0 | 0x4751c4 | 0xa0964 | 0x9f164 | 0x599 |
TlsFree | 0x0 | 0x4751c8 | 0xa0968 | 0x9f168 | 0x597 |
GetSystemTimeAsFileTime | 0x0 | 0x4751cc | 0xa096c | 0x9f16c | 0x2e5 |
GetModuleHandleW | 0x0 | 0x4751d0 | 0xa0970 | 0x9f170 | 0x274 |
GetProcAddress | 0x0 | 0x4751d4 | 0xa0974 | 0x9f174 | 0x2aa |
DuplicateHandle | 0x0 | 0x4751d8 | 0xa0978 | 0x9f178 | 0x129 |
WaitForSingleObjectEx | 0x0 | 0x4751dc | 0xa097c | 0x9f17c | 0x5d0 |
GetCurrentThread | 0x0 | 0x4751e0 | 0xa0980 | 0x9f180 | 0x219 |
GetStringTypeW | 0x0 | 0x4751e4 | 0xa0984 | 0x9f184 | 0x2d3 |
CompareStringW | 0x0 | 0x4751e8 | 0xa0988 | 0x9f188 | 0x9a |
LCMapStringW | 0x0 | 0x4751ec | 0xa098c | 0x9f18c | 0x3ac |
GetLocaleInfoW | 0x0 | 0x4751f0 | 0xa0990 | 0x9f190 | 0x261 |
GetCPInfo | 0x0 | 0x4751f4 | 0xa0994 | 0x9f194 | 0x1bf |
SetEvent | 0x0 | 0x4751f8 | 0xa0998 | 0x9f198 | 0x50e |
ResetEvent | 0x0 | 0x4751fc | 0xa099c | 0x9f19c | 0x4bf |
UnhandledExceptionFilter | 0x0 | 0x475200 | 0xa09a0 | 0x9f1a0 | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x475204 | 0xa09a4 | 0x9f1a4 | 0x565 |
IsDebuggerPresent | 0x0 | 0x475208 | 0xa09a8 | 0x9f1a8 | 0x37a |
GetStartupInfoW | 0x0 | 0x47520c | 0xa09ac | 0x9f1ac | 0x2cc |
GetCurrentProcessId | 0x0 | 0x475210 | 0xa09b0 | 0x9f1b0 | 0x216 |
InitializeSListHead | 0x0 | 0x475214 | 0xa09b4 | 0x9f1b4 | 0x35e |
LocalFree | 0x0 | 0x475218 | 0xa09b8 | 0x9f1b8 | 0x3c9 |
CreateTimerQueue | 0x0 | 0x47521c | 0xa09bc | 0x9f1bc | 0xf8 |
SignalObjectAndWait | 0x0 | 0x475220 | 0xa09c0 | 0x9f1c0 | 0x573 |
CreateThread | 0x0 | 0x475224 | 0xa09c4 | 0x9f1c4 | 0xf1 |
SetThreadPriority | 0x0 | 0x475228 | 0xa09c8 | 0x9f1c8 | 0x556 |
GetThreadPriority | 0x0 | 0x47522c | 0xa09cc | 0x9f1cc | 0x2fd |
GetLogicalProcessorInformation | 0x0 | 0x475230 | 0xa09d0 | 0x9f1d0 | 0x265 |
CreateTimerQueueTimer | 0x0 | 0x475234 | 0xa09d4 | 0x9f1d4 | 0xf9 |
ChangeTimerQueueTimer | 0x0 | 0x475238 | 0xa09d8 | 0x9f1d8 | 0x78 |
DeleteTimerQueueTimer | 0x0 | 0x47523c | 0xa09dc | 0x9f1dc | 0x118 |
GetNumaHighestNodeNumber | 0x0 | 0x475240 | 0xa09e0 | 0x9f1e0 | 0x285 |
GetProcessAffinityMask | 0x0 | 0x475244 | 0xa09e4 | 0x9f1e4 | 0x2ab |
SetThreadAffinityMask | 0x0 | 0x475248 | 0xa09e8 | 0x9f1e8 | 0x54b |
RegisterWaitForSingleObject | 0x0 | 0x47524c | 0xa09ec | 0x9f1ec | 0x4a2 |
UnregisterWait | 0x0 | 0x475250 | 0xa09f0 | 0x9f1f0 | 0x5ae |
GetThreadTimes | 0x0 | 0x475254 | 0xa09f4 | 0x9f1f4 | 0x301 |
FreeLibrary | 0x0 | 0x475258 | 0xa09f8 | 0x9f1f8 | 0x1a9 |
FreeLibraryAndExitThread | 0x0 | 0x47525c | 0xa09fc | 0x9f1fc | 0x1aa |
GetModuleHandleA | 0x0 | 0x475260 | 0xa0a00 | 0x9f200 | 0x271 |
LoadLibraryExW | 0x0 | 0x475264 | 0xa0a04 | 0x9f204 | 0x3be |
GetVersionExW | 0x0 | 0x475268 | 0xa0a08 | 0x9f208 | 0x317 |
VirtualAlloc | 0x0 | 0x47526c | 0xa0a0c | 0x9f20c | 0x5be |
VirtualProtect | 0x0 | 0x475270 | 0xa0a10 | 0x9f210 | 0x5c4 |
VirtualFree | 0x0 | 0x475274 | 0xa0a14 | 0x9f214 | 0x5c1 |
ReleaseSemaphore | 0x0 | 0x475278 | 0xa0a18 | 0x9f218 | 0x4ad |
InterlockedPopEntrySList | 0x0 | 0x47527c | 0xa0a1c | 0x9f21c | 0x369 |
InterlockedPushEntrySList | 0x0 | 0x475280 | 0xa0a20 | 0x9f220 | 0x36a |
InterlockedFlushSList | 0x0 | 0x475284 | 0xa0a24 | 0x9f224 | 0x367 |
QueryDepthSList | 0x0 | 0x475288 | 0xa0a28 | 0x9f228 | 0x43c |
UnregisterWaitEx | 0x0 | 0x47528c | 0xa0a2c | 0x9f22c | 0x5af |
LoadLibraryW | 0x0 | 0x475290 | 0xa0a30 | 0x9f230 | 0x3bf |
RtlUnwind | 0x0 | 0x475294 | 0xa0a34 | 0x9f234 | 0x4cb |
ExitProcess | 0x0 | 0x475298 | 0xa0a38 | 0x9f238 | 0x15c |
ADVAPI32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptExportKey | 0x0 | 0x475000 | 0xa07a0 | 0x9efa0 | 0xd0 |
RegCreateKeyW | 0x0 | 0x475004 | 0xa07a4 | 0x9efa4 | 0x267 |
RegOpenKeyExW | 0x0 | 0x475008 | 0xa07a8 | 0x9efa8 | 0x28c |
RegSetValueExW | 0x0 | 0x47500c | 0xa07ac | 0x9efac | 0x2a9 |
RegCloseKey | 0x0 | 0x475010 | 0xa07b0 | 0x9efb0 | 0x25b |
CryptReleaseContext | 0x0 | 0x475014 | 0xa07b4 | 0x9efb4 | 0xdc |
CryptGenKey | 0x0 | 0x475018 | 0xa07b8 | 0x9efb8 | 0xd1 |
CryptImportKey | 0x0 | 0x47501c | 0xa07bc | 0x9efbc | 0xdb |
OpenProcessToken | 0x0 | 0x475020 | 0xa07c0 | 0x9efc0 | 0x215 |
GetTokenInformation | 0x0 | 0x475024 | 0xa07c4 | 0x9efc4 | 0x170 |
CloseServiceHandle | 0x0 | 0x475028 | 0xa07c8 | 0x9efc8 | 0x65 |
OpenSCManagerW | 0x0 | 0x47502c | 0xa07cc | 0x9efcc | 0x217 |
DeleteService | 0x0 | 0x475030 | 0xa07d0 | 0x9efd0 | 0xec |
ControlService | 0x0 | 0x475034 | 0xa07d4 | 0x9efd4 | 0x6a |
EnumDependentServicesW | 0x0 | 0x475038 | 0xa07d8 | 0x9efd8 | 0x10f |
OpenServiceW | 0x0 | 0x47503c | 0xa07dc | 0x9efdc | 0x219 |
QueryServiceStatusEx | 0x0 | 0x475040 | 0xa07e0 | 0x9efe0 | 0x251 |
CryptDestroyKey | 0x0 | 0x475044 | 0xa07e4 | 0x9efe4 | 0xc8 |
CryptAcquireContextW | 0x0 | 0x475048 | 0xa07e8 | 0x9efe8 | 0xc2 |
CryptEncrypt | 0x0 | 0x47504c | 0xa07ec | 0x9efec | 0xcb |
CryptDuplicateKey | 0x0 | 0x475050 | 0xa07f0 | 0x9eff0 | 0xca |
RegDeleteValueW | 0x0 | 0x475054 | 0xa07f4 | 0x9eff4 | 0x273 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | 0x0 | 0x4752e8 | 0xa0a88 | 0x9f288 | 0x139 |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CLSIDFromString | 0x0 | 0x4752f8 | 0xa0a98 | 0x9f298 | 0xc |
IIDFromString | 0x0 | 0x4752fc | 0xa0a9c | 0x9f29c | 0x102 |
CoInitializeEx | 0x0 | 0x475300 | 0xa0aa0 | 0x9f2a0 | 0x5e |
CoGetObject | 0x0 | 0x475304 | 0xa0aa4 | 0x9f2a4 | 0x51 |
CoInitialize | 0x0 | 0x475308 | 0xa0aa8 | 0x9f2a8 | 0x5d |
CoUninitialize | 0x0 | 0x47530c | 0xa0aac | 0x9f2ac | 0x8d |
CoCreateInstance | 0x0 | 0x475310 | 0xa0ab0 | 0x9f2b0 | 0x28 |
CoInitializeSecurity | 0x0 | 0x475314 | 0xa0ab4 | 0x9f2b4 | 0x5f |
OLEAUT32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringByteLen | 0x96 | 0x4752b4 | 0xa0a54 | 0x9f254 | - |
VariantClear | 0x9 | 0x4752b8 | 0xa0a58 | 0x9f258 | - |
SysAllocString | 0x2 | 0x4752bc | 0xa0a5c | 0x9f25c | - |
SysStringByteLen | 0x95 | 0x4752c0 | 0xa0a60 | 0x9f260 | - |
VariantInit | 0x8 | 0x4752c4 | 0xa0a64 | 0x9f264 | - |
SysFreeString | 0x6 | 0x4752c8 | 0xa0a68 | 0x9f268 | - |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x47505c | 0xa07fc | 0x9effc | 0xe3 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x4752a0 | 0xa0a40 | 0x9f240 | 0x2b |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetApiBufferFree | 0x0 | 0x4752a8 | 0xa0a48 | 0x9f248 | 0x51 |
NetShareEnum | 0x0 | 0x4752ac | 0xa0a4c | 0x9f24c | 0xde |
IPHLPAPI.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpSendEcho | 0x0 | 0x475064 | 0xa0804 | 0x9f004 | 0x91 |
IcmpCloseHandle | 0x0 | 0x475068 | 0xa0808 | 0x9f008 | 0x8e |
GetAdaptersInfo | 0x0 | 0x47506c | 0xa080c | 0x9f00c | 0x40 |
IcmpCreateFile | 0x0 | 0x475070 | 0xa0810 | 0x9f010 | 0x8f |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
inet_addr | 0xb | 0x4752f0 | 0xa0a90 | 0x9f290 | - |
RstrtMgr.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RmShutdown | 0x0 | 0x4752d0 | 0xa0a70 | 0x9f270 | 0xa |
RmRegisterResources | 0x0 | 0x4752d4 | 0xa0a74 | 0x9f274 | 0x6 |
RmStartSession | 0x0 | 0x4752d8 | 0xa0a78 | 0x9f278 | 0xb |
RmGetList | 0x0 | 0x4752dc | 0xa0a7c | 0x9f27c | 0x4 |
RmEndSession | 0x0 | 0x4752e0 | 0xa0a80 | 0x9f280 | 0x2 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
op_new.exe | 1 | 0x003D0000 | 0x0047DFFF | Relevant Image | 32-bit | 0x004233A1 |
...
|
|||
op_new.exe | 1 | 0x003D0000 | 0x0047DFFF | Final Dump | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.MedusaLocker.942644D7 |
Malicious
|
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.VinDizelPux | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.VinDizelPux | Dropped File | Stream |
Unknown
|
...
|
»