9282ffd0f7aef39febc84f33a3090898e2fae6236cae7465a21ca58978d81b86 (SHA256)
r.exe
Created at 2018-03-16 23:07:00
Notifications (2/2)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
5/5
|
File System | Encrypts content of user files | Ransomware | |
|
||||
3/5
|
OS | Modifies certificate store | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
3/5
|
Browser | Reads data related to browser cookies | - | |
|
||||
3/5
|
Browser | Reads data related to saved browser credentials | - | |
|
||||
|
||||
2/5
|
Anti Analysis | Tries to detect virtual machine | - | |
|
||||
2/5
|
Browser | Reads data related to browsing history | - | |
|
||||
1/5
|
Anti Analysis | Resolves APIs dynamically to possibly evade static detection | - | |
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
1/5
|
Network | Performs DNS request | - | |
|
||||
1/5
|
Process | Overwrites code | - | |
|
||||
1/5
|
Network | Checks external IP address | - | |
|
||||
1/5
|
Network | Downloads data | Downloader | |
|
||||
|
||||
1/5
|
Network | Connects to HTTP server | - | |
|
||||
|
||||
1/5
|
PE | Drops PE file | Dropper | |
|
||||
1/5
|
PE | Executes dropped PE file | - | |
|