97328f00...7f6c | VTI
Try VMRay Analyzer
VTI SCORE: 94/100
Target: win7_32_sp1 | exe
Classification: Trojan, Downloader

97328f00d5dc6d72f7a1a5c75e6991135183ffeef10e1a6a49dab7cba2eb7f6c (SHA256)

97328f00d5dc6d72f7a1a5c75e6991135183ffeef10e1a6a49dab7cba2eb7f6c.dll

Windows DLL (x86-32)

Created at 2018-04-29 13:05:00

Notifications (2/2)

This report is associated with a dynamic link library (DLL), which normally needs an appropriate loader. If an appropriate loader was not submitted along with the DLL, the analysis results may be incomplete and may not fully represent the behavior of the sample.

The overall sleep time of all monitored processes was truncated from "3 hours, 58 minutes, 39 seconds" to "40 seconds" to reveal dormant functionality.

Severity Category Operation Classification
4/5
File System Associated with malicious files Trojan
  • File "c:\users\eebsym5\desktop\97328f00d5dc6d72f7a1a5c75e6991135183ffeef10e1a6a49dab7cba2eb7f6c.dll" is a known malicious file.
4/5
Injection Writes into the memory of another running process -
  • "c:\windows\system32\gorctexxzx.exe" modifies memory of "c:\program files\mozilla firefox\firefox.exe"
4/5
Injection Modifies control flow of another process -
  • "c:\windows\system32\gorctexxzx.exe" creates thread in "c:\program files\mozilla firefox\firefox.exe"
1/5
Anti Analysis Resolves APIs dynamically to possibly evade static detection -
1/5
Anti Analysis Delays execution -
1/5
Process Creates process with hidden window -
  • The process "c:\program files\mozilla firefox\firefox.exe" starts with hidden window.
1/5
Process Creates a page with write and execute permissions -
  • Changes the protection of a page in a foreign process from writable ("PAGE_READWRITE") to executable ("PAGE_EXECUTE_READWRITE").
1/5
Network Downloads data Downloader
  • URL "webonline.mefound.com/index/index.php?h=TQz6H5GI8zI%3d&d=TQz%2f%2fCqWZDJNDfUup77CB3U%2bzyihu8MGfTz6H5GI8zJNDPofkYh%3d".
  • URL "webonline.mefound.com/index/index.php?h=ppbto8NHADo%3d&d=ppboQHhZlzqml%2bKS9XExD56k2JTzdDAOlqbto8NHADqmlu2jw0d%3d".
1/5
Network Connects to HTTP server -
  • URL "webonline.mefound.com/index/index.php?h=8NavN1UHP1o%3d&d=8Naq1O4ZqFrw16AGYzEOb8jkmgBlNA9uwOavN1UHP1rw1q83VQd%3d".
  • URL "easport-news.publicvm.com/index/index.php?h=O2i1voZ4%2bOQ%3d&d=OWiwXT1mb%2bQ7abqPsE7J0QNagIm2S8jQC1i1voZ4%2bOQ7aLW%2bhnjJ0g1ZgIa0Tc%2fUCFiBjrY8ydYJXYGHtEHI0BUCxdmmWNjEG0iVnqZY2MQbSJWepljYxM%3d%3d".
  • URL "webonline.mefound.com/index/index.php?h=ppbto8NHADo%3d&d=ppboQHhZlzqml%2bKS9XExD56k2JTzdDAOlqbto8NHADqmlu2jw0d%3d".
  • URL "easport-news.publicvm.com/index/index.php?h=8AsKjDaVkr4%3d&d=8gsPb42LBb7wCgW9AKOji8g5P7sGpqKKwDsKjDaVkr7wCwqMNpWjiMY6P7QEoKWOwzs%2bvAbRo43EPDi8BKyiit5heusWtbKe0CsqrBa1sp7QKyqsFrWyns%3d%3d".
  • URL "webonline.mefound.com/index/index.php?h=OjoH51%2feH88%3d&d=OjoCBOTAiM86OwjWaegu%2bgIIMtBv7S%2f7CgoH51%2feH886OgfnX95%3d".
  • URL "easport-news.publicvm.com/index/index.php?h=TqFIohTtxkA%3d&d=TKFNQa%2fzUUBOoEeTItv3dXaTfZUk3vZ0fpFIohTtxkBOoUiiFO33dniQfZom2PFwfZF8kiSp93V%2blHyRJtT2dGDLOMU0zeZgboFogjTN5mBugWiCNM3mYM%3d%3d".
  • URL "webonline.mefound.com/index/index.php?h=TQz6H5GI8zI%3d&d=TQz%2f%2fCqWZDJNDfUup77CB3U%2bzyihu8MGfTz6H5GI8zJNDPofkYh%3d".
  • URL "easport-news.publicvm.com/index/index.php?h=LIFUEDEFV6c%3d&d=LoFR84obwKcsgFshBzNmkhSzYScBNmeTHLFUEDEFV6csgVQQMQVmkRqwYSgDMGCXH7FgIAFBZpYdtWQhAzxnkwLrJHcRJXeHDKF0MBEld4cMoXQwESV3h8%3d%3d".
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image