VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Trojan.GenericKD.34686589
Gen:Heur.Ransom.Imps.1
Gen:Trojan.Heur.JP.9uX@aKF!nih
...
|
kfjgxo.exe
Windows Exe (x86-32)
Created at 2020-10-09T10:33:00
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "5 minutes" to "10 seconds" to reveal dormant functionality.
Indicators
File (469)
»
Registry (3)
»
Registry Key Name | Operations |
---|---|
HKEY_CURRENT_USER | Access |
HKEY_CURRENT_USER\Software\woodrat | Access, Create |
HKEY_CURRENT_USER\Software\woodrat\sha | Access, Write |
Domain (1)
»
Domain | Sources | Severity |
---|---|---|
xduwtfono | Function Log |
Unknown
|
IP (1)
»
IP | Protocols | Sources |
---|---|---|
192.168.0.198 | DNS | Function Log |