VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Zusy.304957
|
pay.ps1
PowerShell Script
Created at 2020-10-03T16:53:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "15 minutes" to "2 minutes, 30 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\5yhng4j0.0.cs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\5yhng4j0.cmdline | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\5yhng4j0.out | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\7rzn_h_f.0.cs | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\7rzn_h_f.cmdline | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Temp\7rzn_h_f.out | Dropped File | Text |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\cd0bd55954d486c71b.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\da0ad9404ca1d.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\wkvwlodo3dw\7ada2cf9425a4f7b2d.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\msn websites\75a24db1c33c0.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\microsoft websites\a2186765bab2287ebc398.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\contacts\70594b8730601a512b93.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\6b949b733c94109.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\d6b077946517743eeaf.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\contacts\7dfd09db884f191ce16fc1.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\wkvwlodo3dw\vmvtjdsqy.bmp.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\msn websites\9d0cb61ff30952.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\msn websites\f286d531f8a0ec.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\microsoft websites\91a189c3228f5329e6.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\a20bc0edcb9b.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\links\90889449abef1acca20.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\searches\85eca7249d23b7e4a303.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\contacts\7160ee0d7adb463c941b81.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\microsoft websites\33dd1d93a45c8a33c4e69d05bff1.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\09c09813.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\microsoft websites\faaec0860b51874de436c.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\pictures\hvlzha2l.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\vw_ylonl3fam5py\yg4f3-6jbhnwho2gj8.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\pictures\m_g ycxgr-cfx2.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\iskpn-oaeg.doc.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\zlenn.bmp.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\122aed86a22b774983221129.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\links\ae88b4b4c30e1b760f562.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\a4944b4a0f1d.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\f5a66424f590.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\contacts\20772312cecf50c477dcc4.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\1e2e2ea0c4c3b.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\msn websites\75a80b0.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\microsoft websites\4c52706eab7129441d8.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\favorites\msn websites\2e1e096bdcd8e863770ae.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\dched.docx.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\f70cd77e6938d736410.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\8e27b77cf33ff.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\dmeebdwzu35ue8\0a709c3bc9d6145028f78.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\uyodi-5ywpl3.docx.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\zsnh30orzmyzl6pbdir.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\90016192.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\ejyccmut1.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\ktpf3a_0bbexx5rwtf-u.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\6729092e1843fb4d9e88e.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\572e6d0053578e0e7ed1a.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\4ez86z4hqqd5wk_s1z2\039e2c91faeddf5de.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\993daa640f8d197aaff175.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\19e6428947.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\d445175ff937c608.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\9ff72a67e5c5b289f245.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\5a358172ceef7ae524f62b8d.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\214f2a22ecab2c32390c06.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\dwck9.jpg.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\public\libraries\a8e23a774e3fe98fc69e1.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\tj7hmjccmkr7r9oo4hji\kxe l9\mhdqby\f99487bdc.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\dmeebdwzu35ue8\2b9e8628b0af62f.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\d45643359124b14a5ee8b16a.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\p_tksnph.docx.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\a7945bb76d83666ded0025.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\0e4e5817346e4169b.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\fd3970ac521f42e16.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\0203f326af055b2d38977.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\roaming\dsxj_2rfxzoit_cemfh.bmp.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\w7n5fhz2t34fcqfi.jpg.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\ygvdfl\k1effx06kg7atc\690d97f0e1ad20.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\ygvdfl\q3s-6c\4445c34e8f477.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\-ixq1 4vszrqo_\4f8a1fba111aa.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\tj7hmjccmkr7r9oo4hji\zygsl\4176811b01.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\u0e_xfok\62208536.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\documents\-n9-kuy\u0e_xfok\637100ee313e3.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\-ixq1 4vszrqo_\3e2a358f63f49327115b87.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\-ixq1 4vszrqo_\9a47213ed59b74da691539.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\videos\-ixq1 4vszrqo_\df25c1c2da421.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\pictures\wrmmz2_y1ukgt0z1\rdrojurtfoy.bmp.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\pictures\wrmmz2_y1ukgt0z1\f5e94ea9781dde03.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\music\tj7hmjccmkr7r9oo4hji\zygsl\85e14a0db9c.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\cda8cf5c7503ee6be.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\bc3ae4658a9c1f4345bf.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\bauateq-1x.bmp.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\80846648e097d377ae.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\0646b62cb8bb9b8e.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\6cafc417fa0f82c6.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\5fd7c95c180c1.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\5efef1ff27cc27be5e11a3e3.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\3e870400e4948fc5adc87741.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\desktop\0a68c1226ebe60c30.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\_metadata\909b9e9947ef69fd731672.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\it\754a7f095e36c.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\de\b8eb7a84306b3.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ca\c5cd861475f4f.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ar\bede4af9badb4.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\nl\1bbcfe895aa8f.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\3a88b1141c0.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\584a31a37f5d0363bae5.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\bg\850e68ece9daa.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\de\421f83cbece50.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\5280a16787902.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lv\254a7576d2b92.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\ja\fa09583edd8cb.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\lt\21096107623c6.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\id\00a8053fc8665.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\hr\cd81a6888db92.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fi\2eebd0c0a31f6.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\css\a331e85847c8024.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\en\ae77b1a9808f1.68814f | Dropped File | Binary |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\es\cc96f5acf9356.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\fil\5c395dd377100.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_hover.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_16.png.68814f | Dropped File | Binary |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\1b198f29a200a2429ab3.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\_metadata\0156478bd985a5409efcfc.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_pressed.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_close.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_maximize.png.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\se\801d50b1e122c.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\lt\06d10da4fbfde.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\id\c8a6449dad0c1.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\it\c41d6b6c0cd68.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ko\c06c48612aef8.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\57aad1297dac62293ebd22.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\_locales\ja\a9bc781af0752.68814f | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\eebsym5\appdata\local\google\chrome\user data\default\extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\html\d7e5ca748a351514.68814f | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\EEBsYm5\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\_locales\el\68814F-Readme.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\Users\EEBsYm5\AppData\Local\Temp\CSC2116.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»