75620d6a...595a | VTI
Try VMRay Analyzer
VTI SCORE: 93/100
Dynamic Analysis Report
Classification: Trojan, Wiper, Downloader

75620d6ae02a9a3beb5eb47020012eee52001bf434304f4e77b43011a6e5595a (SHA256)

CrazyCrypt.exe

Windows Exe (x86-32)

Created at 2019-02-28 11:07:00

Severity Category Operation Classification
4/5
File System Deletes user files Wiper
  • Deletes multiple user files. This is an indicator for ransomware or wiper malware.
3/5
OS Modifies system security configuration -
2/5
File System Known suspicious file Trojan
  • File "C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CrazyCrypt.exe" is a known suspicious file.
1/5
Process Creates system object -
1/5
Anti Analysis Resolves APIs dynamically -
1/5
Persistence Installs system startup script or application -
  • Adds "c:\programdata\microsoft\windows\start menu\programs\startup" to Windows startup folder.
  • Adds "c:\users\all users\microsoft\windows\start menu\programs\startup" to Windows startup folder.
1/5
Network Performs DNS request -
1/5
Static Unparsable sections in file -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CrazyCrypt.exe.
1/5
Network Connects to remote host -
1/5
Network Downloads data Downloader
  • URL "http://crazycrypt.store/requests/write.php?computer_name=XDUWTFONO&userName=5p5NrGJn0jS%20HALPmcxz&password=9C354B42".
1/5
Network Connects to HTTP server -
  • URL "crazycrypt.store/requests/write.php?computer_name=XDUWTFONO&userName=5p5NrGJn0jS%20HALPmcxz&password=9C354B42".
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image