VMRay Analyzer Report
Analysis Information
Creation Time2016-10-13 15:41 (UTC+2)
VM Analysis Duration Time00:02:42
Execution SuccessfulTrue
Sample FilenameTax Tool.exe
Command Line ParametersFalse
PrescriptFalse
Number of Processes5
Termination ReasonTimeout
Download Function Logfile Generic Logfile PCAP STIX/CybOX
VTI Information
VTI Score
75 / 100
VTI Database Version2.2
VTI Rule Match Count30
VTI Rule TypeDefault (PE, ...)
Tags
The tags feature is only available in the fully licensed version of VMRay Analyzer.
Screenshots
Screenshot Screenshot Screenshot Screenshot
Monitored Processes
Process Graph


IDPIDMonitor ReasonImage NameCommand LineOrigin ID
#10x990Analysis Targettax tool.exe"C:\Users\WI2yhmtI onvScY7Pe\Desktop\Tax Tool.exe"
#20x84Child Processdevices.exe"C:\Users\WI2yhmtI onvScY7Pe\AppData\Roaming\Sun\Java\Devices.exe"#1
#30x2ecChild Processsvchost.exeC:\Windows\SysWOW64\svchost.exe -k netsvcs#2
#40xc54Child Processsvchost.exeC:\Windows\SysWOW64\svchost.exe -k netsvcs#2
#50xcacChild Processcmd.exe"C:\Windows\system32\cmd.exe" /c "C:\Users\WI2YHM~1\AppData\Local\Temp\upd823d0e12.bat"#1
Sample Information
ID#625180
MD5 Hash Value212ba96c626898e00e140d5fb3230dd8
SHA1 Hash Value204764a6e5f7b2426274da728ee07927b813f68d
SHA256 Hash Valueec2504089edf0330d58433079b2a5f72c102582c399ad73c59777ee03363929a
FilenameTax Tool.exe
File Size121.50 KB (124416 bytes)
File TypeWindows Exe (x86-32)
Analyzer and Virtual Machine Information
Analyzer Version1.11.0
Analyzer Build Date2016-09-19 10:58 (UTC+2)
VM Namewin10_64
VM DescriptionWindows 10 (64-bit)
VM Architecturex86 64-bit
VM OSWindows 10
VM Kernel Version10.0.10240.16384 (c68ee22f-dcf6-4778-95c5-4a862be16567)
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image