7558b47e...d5b9 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Downloader, Trojan

VMRay Threat Indicators (21 rules, 42 matches)

Severity Category Operation Count Classification
5/5
Local AV Malicious content was detected by heuristic scan 2 -
4/5
File System Modifies content of user files 1 Ransomware
  • Modifies the content of multiple user files. This is an indicator for an encryption attempt.
4/5
File System Renames user files 1 Ransomware
  • Renames multiple user files. This is an indicator for an encryption attempt.
4/5
Reputation Known malicious URL 3 -
  • Contacted URL "h139975.s08.test-hf.su/SmailFile/1.jpg" is a known malicious URL.
  • Contacted URL "h139975.s08.test-hf.su/SmailFile/Hermes-decrypter-new.exe" is a known malicious URL.
  • Contacted URL "h139975.s08.test-hf.su" is a known malicious URL.
3/5
Anti Analysis Tries to evade debugger 1 -
3/5
Network Reads network adapter information 1 -
2/5
Anti Analysis Tries to detect debugger 3 -
2/5
Anti Analysis Tries to detect kernel debugger 1 -
2/5
OS Changes the desktop wallpaper. 3 -
2/5
Anti Analysis Tries to detect virtual machine 1 -
  • Possibly trying to detect VM via rdtsc.
2/5
Anti Analysis Makes direct system call to possibly evade hooking based sandboxes 8 -
  • Makes a direct system call to "NtQueryInformationProcess".
  • Makes a direct system call to "NtSetInformationThread".
  • Makes a direct system call to "NtOpenFile".
  • Makes a direct system call to "NtCreateSection".
  • Makes a direct system call to "NtMapViewOfSection".
  • Makes a direct system call to "NtClose".
  • Makes a direct system call to "NtProtectVirtualMemory".
  • Makes a direct system call to "NtQueryVirtualMemory".
2/5
Reputation Known suspicious file 2 Trojan
  • File "C:\Users\FD1HVy\Desktop\Hermes.exe" is a known suspicious file.
1/5
Network Performs DNS request 3 -
1/5
Persistence Installs system startup script or application 1 -
  • Adds "C:\FD1HVy\Hermes-decrypter-new.exe" to Windows startup via registry.
1/5
Device Monitors mouse movements and clicks 1 -
  • Frequently reads the state of a mouse button by API.
1/5
File System Creates an unusually large number of files 1 -
1/5
Network Connects to remote host 3 -
  • Outgoing TCP connection to host "172.217.22.36:443".
  • Outgoing TCP connection to host "5.101.152.98:80".
  • Outgoing TCP connection to host "91.227.16.118:80".
1/5
Network Downloads file 1 -
1/5
Network Downloads executable 1 Downloader
1/5
Network Connects to HTTP server 3 -
  • URL "h139975.s08.test-hf.su/SmailFile/Hermes-decrypter-new.exe".
  • URL "giftshop.host/write.php?computer_name=NQDPDE&userName=FD1HVy&password=lV5MTdp=(I8f9TR&allow=ransom".
1/5
Static Unparsable sections in file 1 -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\FD1HVy\Desktop\Hermes.exe.

Screenshots

Monitored Processes

Sample Information

ID #661271
MD5 834ff8a44652ebeb620bffe8a945de03 Copy to Clipboard
SHA1 97e2f8ae51c63baaf9340776666d9bed272db38f Copy to Clipboard
SHA256 7558b47e44541d2417d91ce9308ada497f41fb2f550d9bc43231634fe2c1d5b9 Copy to Clipboard
SSDeep 98304:QzHoxAJ5v1XlxuRSptA3mz9CKfHGFUWWsgkSeL2wmidHHoWv/heIY:42Ar1VxuRSptUmz9J3kSeLCAH3/RY Copy to Clipboard
ImpHash 0f95a431ac4033f952fb4eecc31cf15d Copy to Clipboard
Filename Hermes.exe
File Size 5.38 MB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-05-24 18:55 (UTC+2)
Analysis Duration 00:04:43
Number of Monitored Processes 3
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
Local AV Enabled True
YARA Enabled True
Number of AV Matches 2
Number of YARA Matches 0
Termination Reason Timeout
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image