VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Ransom.HiddenTears.1
|
DRV.exe
Windows Exe (x86-32)
Created at 2020-02-02T05:24:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41cf02 |
Size Of Code | 0x1b000 |
Size Of Initialized Data | 0x19a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-25 09:36:35+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.2 |
Comments | Education |
CompanyName | |
FileDescription | Education |
FileVersion | 1.0.0.2 |
InternalName | DRV.exe |
LegalCopyright | Copyright © Edu 2019 |
LegalTrademarks | - |
OriginalFilename | DRV.exe |
ProductName | Edu |
ProductVersion | 1.0.0.2 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1af10 | 0x1b000 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.62 |
.rsrc | 0x41e000 | 0x19790 | 0x19800 | 0x1b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.46 |
.reloc | 0x438000 | 0xc | 0x200 | 0x34a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1ced8 | 0x1b0d8 | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.HiddenTears.1 |
Malicious
|
C:\Users\FD1HVy\Desktop\1JxO_9PkYpJjuANc0MYY.mp3.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3WyJwIV.mkv.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6hhjTWOjzCfu0rnA4.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6HNjkXmD.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\a3sRI6Cz-JPY f ZrF.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\CJ1dJ8X-Q1z.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\EfWJiIx3a_1d.mkv.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\f3Gzb_50kjr.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hNiCTsHx0td64.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kd0zALJ7DL1 jJ.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\O15DVK-lET.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\YTzF2.png.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zW2EXfEbpSjZ.jpg.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tjkDB\s6jTWhN.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tjkDB\zh5eIwpTSvJ6-u\FSvL.xls.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tjkDB\zh5eIwpTSvJ6-u\_-VbrQQyn1DsWjhmXs3i\g37XiZb8esLM1okfimAp.mp3.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tjkDB\zh5eIwpTSvJ6-u\_-VbrQQyn1DsWjhmXs3i\zg2n9UmmG_jnYm.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\16UFpUYc.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\6xnE8Bqvdaf.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\7exp xTRzv46z0.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eNstC9sFkdSrn_zm.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\f7wibkMFM.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Gaw9-G.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hKevxhjgOViZvmb4dgsM.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\IonqQ.xlsx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\JbQgGtR9f8.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\kk5RsZWzB1.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\m8WvuP-u1PN.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\tPN QnS.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\uiCWZEiYxUOkHQV75oaw.xlsx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\UrlrFmtr6vZgKIDop.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\V1jsrNdhVIe iWy.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\VAXCZS.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\YRc1yr238uNyMIyw3LMt.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\3tlU8m0FGdaJC.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\IVJMM0.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\JG-1HMBe9K0.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\QkbZJThCSe8MyH6CTYZ.csv | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\v7XZOCEf F1 wN.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\Gaq_qhpbNEP yA5\dpS2puE.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\Gaq_qhpbNEP yA5\HR-RUVa.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\Gaq_qhpbNEP yA5\Ks4DRHQJOykTzQ-.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\Gaq_qhpbNEP yA5\Nq4ui\r4Tug2RUXDiTeI XCvb4.csv | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\pVUiS6J1G2H6V\j0UC.odt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\pVUiS6J1G2H6V\ZEkOtzIx v.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\pVUiS6J1G2H6V\g5HB21GL-08iMMDQ\ZzQQQJIx8cTMARLhBQn.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\xRCw__t\K6Uml2NK6eWnok.csv.lasan | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\xRCw__t\vgwmSrMPoA6aKiQujUz.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\xRCw__t\hrUY_IUYrJwMTueFug\rsrahNgcPwn5cj80UBZU.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2Oa9KcQ A7d\xRCw__t\hrUY_IUYrJwMTueFug\v12r.csv.lasan | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Password.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Password.txt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_ME.txt | Dropped File | Text |
Unknown
|
...
|
»